Snort mailing list archives
Snort running but no alert show in ACID
From: <michela.gandolfo_external () wartsila com>
Date: Thu, 8 Apr 2004 11:12:03 +0200
Hello, I'm running snort on a Red Hat 9 with mysql db and ACID. All was working fine but at a certain point, I don't know the reason, alerts stop to be logged on db and obviously to be displayed through ACID. I try to see if packets was arriving to the nic using tcpdump and it works. Now the strange thing: if I run simultaneously snort (as a daemon) and tcpdump (by command line) on the same interface, alerts are logged again in the db and displayed through ACID. I thought that some how the nic is not put in promiscuous mode when snort starts, so I tried to set it manually (ifconfig eth01 promisc) but sill alerts are not displayed without tcpdump running. Anyone has a suggestion for me? Thanks for your help Best Regards Michela Gandolfo ************************************************ This e-mail is from Wärtsilä Italia and it is intended only for the adressee. This e-mail may contain privileged and confidential information. If you receive this e-mail by mistake, please return it to Wärtsilä Italia without distributing or retaining copies thereof. Thank you. ************************************************
Current thread:
- Snort running but no alert show in ACID michela.gandolfo_external (Apr 08)