Snort mailing list archives

Snort running but no alert show in ACID


From: <michela.gandolfo_external () wartsila com>
Date: Thu, 8 Apr 2004 11:12:03 +0200

Hello,
I'm running snort on a Red Hat 9 with mysql db and ACID.
All was working  fine but at a certain point, I don't know the reason, alerts stop to be logged on db and obviously to 
be displayed through ACID.

I try to see if packets was arriving to the nic using tcpdump and it works.
Now the strange thing: if I run simultaneously snort (as a daemon) and tcpdump (by command line) on the same interface, 
alerts are logged again in the db and displayed through ACID.

I thought that some how the nic is not put in promiscuous mode when snort starts, so I tried to set it manually 
(ifconfig eth01 promisc) but sill alerts are not displayed without tcpdump running.

Anyone has a suggestion for me?

Thanks for your help
Best Regards
Michela Gandolfo

************************************************
 
This e-mail is from Wärtsilä Italia and it is intended only for the adressee. This e-mail may contain privileged and 
confidential information. If you receive this e-mail by mistake, please return it to Wärtsilä Italia without 
distributing or retaining copies thereof. Thank you.
 
************************************************
 



Current thread: