Snort mailing list archives

RE: Access denied for user: '@192.168.0.1' -SNORT-


From: "L. Christopher Luther" <CLuther () Xybernaut com>
Date: Tue, 11 Feb 2003 16:29:39 -0500

From my quick look over what you provided, everything does seem to look ok
(I presume that you removed the 'password=' parameter for your MySQL
database or maybe you don't have a password...).  

However, I notice that in your snort.conf you do not have the alert facility
activated.  I don't think Snort uses a default alert facility (I could be
*very* wrong), so I would add an 'output alert_fast: ...' statement to
snort.conf.  

After you do this and restart Snort, try scanning your network from the
outside using NMAP or some other tool.  If Snort is working correctly, you
should get alert messages logged to the file you specify in the alert_fast
plugin.  

- Christopher 


-----Original Message-----
[...snip]
## Output Modules
## --------------
output database: log, mysql, dbname=snort user=sensor1 host=192.168.0.69 
port=3306 sensor_name=Sensor1 detail=full
[snip...]


Current thread: