Snort mailing list archives
Re: alert_full won't create subdirectories for ip addresses when mysql logging is enabled
From: "Andrew R. Baker" <andrewb () snort org>
Date: Fri, 29 Nov 2002 11:04:03 -0500
Peter Schobel wrote:
I have been searching the lists and have found a few posts on this problem but couldn't find any posts that described a resolutionI am usingoutput alert_full output alert_syslog: LOG_AUTH LOG_ALERTand output database: log, mysql, user=user password=pass dbname=snortlogs host=localhostas soon as I turn on the database output, the ip address subdirectories in /var/log/snort are not created, when the database logging is disabled, functionality returns to normal I am starting snort withdaemon /usr/sbin/snort-mysql -l /var/log/snort -D -p\ -i $INTERFACE -c /etc/snort/snort.conf
If you are looking for the sub-directory output, you need to enable the log_ascii output plugin. The reason you see them when you have the database output plugin disabled is because log_ascii is the default packet logging mechanism.
-A -------------------------------------------------------This SF.net email is sponsored by: Get the new Palm Tungsten T handheld. Power & Color in a compact size! http://ads.sourceforge.net/cgi-bin/redirect.pl?palm0002en
_______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- alert_full won't create subdirectories for ip addresses when mysql logging is enabled Peter Schobel (Nov 29)
- Re: alert_full won't create subdirectories for ip addresses when mysql logging is enabled Andrew R. Baker (Nov 29)
- ACID SQL error Faber Fedor (Nov 29)
- <Possible follow-ups>
- RE: alert_full won't create subdirectories for ip addresses when mysql logging is enabled L. Christopher Luther (Dec 02)
- Re: alert_full won't create subdirectories for ip addresses when mysql logging is enabled Andrew R. Baker (Dec 02)
- FW: Re: alert_full won't create subdirectories for ip addresses when mysql logging is enabled Frank Knobbe (Dec 04)