Snort mailing list archives

I wanna log packets to database of which the ip_src is my own pc, but failed.


From: "Kinka" <xcst () qq com>
Date: Mon, 12 Dec 2011 08:56:43 +0800

I wanna log packets to database of which the ip_src is my own pc,but failed. 
I'm using snort in win7. 
We know that using snort in its sniffer mode we can log a lot packets 
into a file, and now I want to log them to a mysql server. I enabled 
the database output plugin in the snort.conf and customed a rule: log 
icmp any any <> any any (sid:1;) as test. Everything is OK and I used 
a PC who's ip is 172.18.186.186 to ping another 172.18.186.189. What I 
hope to get is 8 records,among which there would be 4 records and 
their ip_src are 172.18.186.186. However I just got 4 records and 
their ip_dst are 172.18.186.186 while the ip_src are 172.18.186.186. 
OK,that's my problem. How can I get the 8 records I want to see? Could 
it possible? 
Thanks in advance.
------------------------------------------------------------------------------
Learn Windows Azure Live!  Tuesday, Dec 13, 2011
Microsoft is holding a special Learn Windows Azure training event for 
developers. It will provide a great way to learn Windows Azure and what it 
provides. You can attend the event by watching it streamed LIVE online.  
Learn more at http://p.sf.net/sfu/ms-windowsazure
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: