Snort mailing list archives

Output plugins -differences between logging methods?


From: "Rockoff, Dan" <dan.rockoff () sungard com>
Date: Fri, 25 Jan 2002 11:39:38 -0500

I have successfully set up snort logging to a MySql database, and it has
been running fine for over a month now with no problems.

I am curious however what the differences are between the "output database:
log, and output database: alert" functions.

If I have both enabled, it looks like I get duplicate data for most hits
with the exception of portscans.

Should I just use alert, or am I losing something by not using the "log"
facility?

Thanks.

Current thread: