Snort mailing list archives
Re: mysql support is not compiled into this build of snort
From: "Al Lewis \(allewi\) via Snort-users" <snort-users () lists snort org>
Date: Sat, 7 Apr 2018 11:25:33 +0000
Try using an updated version of snort compiled from source. 2.6 has been gone for ages. Albert Lewis ENGINEER.SOFTWARE ENGINEERING Cisco Systems Inc. Email: allewi () cisco com<mailto:allewi () cisco com> From: Snort-users <snort-users-bounces () lists snort org> on behalf of 2014/2015 - Nsabimana Thierry <thierry.nsabimana () aims-cameroon org> Date: Saturday, April 7, 2018 at 4:46 AM To: "snort-users () lists snort org" <snort-users () lists snort org> Subject: [Snort-users] mysql support is not compiled into this build of snort Hello everyone, I installed snort-2.6.0 and mysql. Then I configured the mysql database for snort. after setting, I tested snort to see whether It can work correctly but I found the error that can be seen below. Could you please help me to overcome this issue? Thanks. root@172-10-228-37:~/snorttmp/snort-2.6.0# snort -c /etc/snort/snort.conf Running in IDS mode --== Initializing Snort ==-- Initializing Output Plugins! Initializing Preprocessors! Initializing Plug-ins! Parsing Rules file /etc/snort/snort.conf +++++++++++++++++++++++++++++++++++++++++++++++++++ Initializing rule chains... Var 'EXTERNAL_NET' defined, value len = 15 chars, value = !192.168.0.5/32<http://192.168.0.5/32> Var 'DNS_SERVERS' defined, value len = 14 chars, value = 192.168.0.5/32<http://192.168.0.5/32> Var 'SMTP_SERVERS' defined, value len = 14 chars, value = 192.168.0.5/32<http://192.168.0.5/32> Var 'HTTP_SERVERS' defined, value len = 14 chars, value = 192.168.0.5/32<http://192.168.0.5/32> Var 'SQL_SERVERS' defined, value len = 14 chars, value = 192.168.0.5/32<http://192.168.0.5/32> Var 'TELNET_SERVERS' defined, value len = 14 chars, value = 192.168.0.5/32<http://192.168.0.5/32> Var 'SNMP_SERVERS' defined, value len = 14 chars, value = 192.168.0.5/32<http://192.168.0.5/32> Var 'HTTP_PORTS' defined, value len = 2 chars, value = 80 Var 'SHELLCODE_PORTS' defined, value len = 3 chars, value = !80 Var 'ORACLE_PORTS' defined, value len = 4 chars, value = 1521 Var 'AIM_SERVERS' defined, value len = 185 chars [64.12.24.0/23,64.12.28.0/23,64.12.161.0/24,64.12.163.0/24,64.12.200.0/24,205.188.3.0/24,205.188.5.0/24,205.188.7.0/24,205.188.9<http://64.12.24.0/23,64.12.28.0/23,64.12.161.0/24,64.12.163.0/24,64.12.200.0/24,205.188.3.0/24,205.188.5.0/24,205.188.7.0/24,205.188.9> .0/24,205.188.153.0/24,205.188.179.0/24,205.188.248.0/24<http://205.188.153.0/24,205.188.179.0/24,205.188.248.0/24>] Var 'RULE_PATH' defined, value len = 16 chars, value = /etc/snort/rules ,-----------[Flow Config]---------------------- | Stats Interval: 0 | Hash Method: 2 | Memcap: 10485760 | Rows : 4099 | Overhead Bytes: 32800(%0.31) `---------------------------------------------- Frag3 global config: Max frags: 65536 Fragment memory cap: 4194304 bytes Frag3 engine config: Target-based policy: FIRST Fragment timeout: 60 seconds Fragment min_ttl: 1 Fragment ttl_limit: 5 Fragment Problems: 1 Bound Addresses: 0.0.0.0/0.0.0.0<http://0.0.0.0/0.0.0.0> Stream4 config: Stateful inspection: ACTIVE Session statistics: INACTIVE Session timeout: 30 seconds Session memory cap: 8388608 bytes Session count max: 8192 sessions Session cleanup count: 5 State alerts: INACTIVE Evasion alerts: INACTIVE Scan alerts: INACTIVE Log Flushed Streams: INACTIVE MinTTL: 1 TTL Limit: 5 Async Link: 0 State Protection: 0 Self preservation threshold: 50 Self preservation period: 90 Suspend threshold: 200 Suspend period: 30 Enforce TCP State: INACTIVE Midstream Drop Alerts: INACTIVE Server Data Inspection Limit: -1 WARNING /etc/snort/snort.conf(409) => flush_behavior set in config file, using old static flushpoints (0) Stream4_reassemble config: Server reassembly: INACTIVE Client reassembly: ACTIVE Reassembler alerts: ACTIVE Zero out flushed packets: INACTIVE Flush stream on alert: INACTIVE flush_data_diff_size: 500 Reassembler Packet Preferance : Favor Old Packet Sequence Overlap Limit: -1 Flush behavior: Small (<255 bytes) Ports: 21 23 25 42 53 80 110 111 135 136 137 139 143 445 513 1433 1521 3306 Emergency Ports: 21 23 25 42 53 80 110 111 135 136 137 139 143 445 513 1433 1521 3306 HttpInspect Config: GLOBAL CONFIG Max Pipeline Requests: 0 Inspection Type: STATELESS Detect Proxy Usage: NO IIS Unicode Map Filename: /etc/snort/unicode.map IIS Unicode Map Codepage: 1252 DEFAULT SERVER CONFIG: Ports: 80 8080 8180 Flow Depth: 300 Max Chunk Length: 500000 Inspect Pipeline Requests: YES URI Discovery Strict Mode: NO Allow Proxy Usage: NO Disable Alerting: NO Oversize Dir Length: 500 Only inspect URI: NO Ascii: YES alert: NO Double Decoding: YES alert: YES %U Encoding: YES alert: YES Bare Byte: YES alert: YES Base36: OFF UTF 8: OFF IIS Unicode: YES alert: YES Multiple Slash: YES alert: NO IIS Backslash: YES alert: NO Directory Traversal: YES alert: NO Web Root Traversal: YES alert: YES Apache WhiteSpace: YES alert: NO IIS Delimiter: YES alert: NO IIS Unicode Map: GLOBAL IIS UNICODE MAP CONFIG Non-RFC Compliant Characters: NONE rpc_decode arguments: Ports to decode RPC on: 111 32771 alert_fragments: INACTIVE alert_large_fragments: ACTIVE alert_incomplete: ACTIVE alert_multiple_requests: ACTIVE Portscan Detection Config: Detect Protocols: TCP UDP ICMP IP Detect Scan Type: portscan portsweep decoy_portscan distributed_portscan Sensitivity Level: Low Memcap (in bytes): 10000000 Number of Nodes: 26109 2834 Snort rules read... 2834 Option Chains linked into 213 Chain Headers 0 Dynamic rules +++++++++++++++++++++++++++++++++++++++++++++++++++ Tagged Packet Limit: 256 +-----------------------[thresholding-config]---------------------------------- | memory-cap : 1048576 bytes +-----------------------[thresholding-global]---------------------------------- | none +-----------------------[thresholding-local]----------------------------------- | gen-id=1 sig-id=2924 type=Threshold tracking=dst count=10 seconds=60 | gen-id=1 sig-id=2275 type=Threshold tracking=dst count=5 seconds=60 | gen-id=1 sig-id=3543 type=Threshold tracking=src count=5 seconds=2 | gen-id=1 sig-id=3152 type=Threshold tracking=src count=5 seconds=2 | gen-id=1 sig-id=3542 type=Threshold tracking=src count=5 seconds=2 | gen-id=1 sig-id=2495 type=Both tracking=dst count=20 seconds=60 | gen-id=1 sig-id=3527 type=Limit tracking=dst count=5 seconds=60 | gen-id=1 sig-id=2923 type=Threshold tracking=dst count=10 seconds=60 | gen-id=1 sig-id=3273 type=Threshold tracking=src count=5 seconds=2 | gen-id=1 sig-id=2494 type=Both tracking=dst count=20 seconds=60 | gen-id=1 sig-id=2496 type=Both tracking=dst count=20 seconds=60 | gen-id=1 sig-id=2523 type=Both tracking=dst count=10 seconds=10 +-----------------------[suppression]------------------------------------------ | none ------------------------------------------------------------------------------- Rule application order: ->activation->dynamic->pass->drop->alert->log Log directory = /var/log/snort Verifying Preprocessor Configurations! Warning: flowbits key 'dce.bind.veritas' is set but not ever checked. Warning: flowbits key 'realplayer.playlist' is checked but not ever set. Warning: flowbits key 'ms_sql_seen_dns' is checked but not ever set. Warning: flowbits key 'smb.tree.create.llsrpc' is set but not ever checked. *** *** interface device lookup found: enp0s25 *** Initializing Network Interface enp0s25 Var 'enp0s25_ADDRESS' defined, value len = 26 chars, value = 192.168.20.0/255.255.255.0<http://192.168.20.0/255.255.255.0> Decoding Ethernet on interface enp0s25 database: compiled support for ( ) database: configured to use mysql database: 'mysql' support is not compiled into this build of snort ERROR: If this build of snort was obtained as a binary distribution (e.g., rpm, or Windows), then check for alternate builds that contains the necessary 'mysql' support. If this build of snort was compiled by you, then re-run the the ./configure script using the '--with-mysql' switch. For non-standard installations of a database, the '--with-mysql=DIR' syntax may need to be used to specify the base directory of the DB install. See the database documentation for cursory details (doc/README.database). and the URL to the most recent database plugin documentation. Fatal Error, Quitting.. -- [https://docs.google.com/uc?export=download&id=0B8jpipaJicbYWlVIQmdVYVBvTGc&revid=0B8jpipaJicbYNUpwTmhSaVVPdXZheVVjQnVKc3RlTVdpSk00PQ] PhD Student In Computer Science University of Abomey Calavi, IMSP Email: thierry.nsabimana () aims-cameroon org<mailto:thierry.nsabimana () aims-cameroon org> Email: thierry.nsabimana () imsp-uac org<mailto:thierry.nsabimana () aims-cameroon org> Tel: +229 61 403 104 AIMS-CAMEROON ALUMNI
_______________________________________________ Snort-users mailing list Snort-users () lists snort org Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
Current thread:
- mysql support is not compiled into this build of snort 2014/2015 - Nsabimana Thierry (Apr 07)
- Re: mysql support is not compiled into this build of snort Al Lewis (allewi) via Snort-users (Apr 07)
- Re: mysql support is not compiled into this build of snort wkitty42 (Apr 07)
- Re: mysql support is not compiled into this build of snort Marcin Dulak via Snort-users (Apr 07)
- Re: mysql support is not compiled into this build of snort wkitty42 (Apr 07)
- Re: mysql support is not compiled into this build of snort Joel Esler (jesler) via Snort-users (Apr 07)
- Re: mysql support is not compiled into this build of snort Jim Campbell (Apr 08)
- Re: mysql support is not compiled into this build of snort wkitty42 (Apr 08)
- Re: mysql support is not compiled into this build of snort 2014/2015 - Nsabimana Thierry (Apr 08)
- Re: mysql support is not compiled into this build of snort Marcin Dulak via Snort-users (Apr 07)