Snort mailing list archives
Output plugins -differences between logging methods?
From: "Rockoff, Dan" <dan.rockoff () sungard com>
Date: Fri, 25 Jan 2002 11:39:38 -0500
I have successfully set up snort logging to a MySql database, and it has been running fine for over a month now with no problems. I am curious however what the differences are between the "output database: log, and output database: alert" functions. If I have both enabled, it looks like I get duplicate data for most hits with the exception of portscans. Should I just use alert, or am I losing something by not using the "log" facility? Thanks.
Current thread:
- Output plugins -differences between logging methods? Rockoff, Dan (Jan 25)
- Re: Output plugins -differences between logging methods? Saad Kadhi (Jan 25)