Snort mailing list archives

SNORT+Mysql trouble!?


From: "SNORT" <snort () cracker dk>
Date: Mon, 10 Mar 2003 13:10:30 +0100

Hello, 

I have got a big problem! 8(

I have setup a openbsd 3.2 bridge firewall with 3 NIC's. 2 NIC's are used for the bridge firewall and the last NIC is 
used to connect to the fw from my labtop to SNORT on the fw. The labtop has apache with ACID. But when labtop is not 
connected the 3. NIC is down.
I have installed SNORT with Mysql. 

The NIC's used are 2 3COM (xl0, xl1) and a standard NIC that comes with the IBM Server (fxp0)

I have removed the domain name for all  the files in the /etc. 

It seems to work fine, the firewall works and when i run SNORT it seems to work fine...but after about 5-10 min it 
stops and says:

sm-msp-queue[13609]: unable to qualify my own domain name (localhost) -- using short name

Also, fx. if i run a portscan on one of the servers behind the Openbsd fw with snort running i get this error and snort 
stops:

snort: database: mysql_error: Duplicate entry '1-100' for key 1 SQL=INSERT INTO event (sid,cid,signature,timestamp) 
VALUES ('1', '100', '1', '2003-03-09 20:24:36+00')

What the f..... am i doing wrong?!! 8(

Please help me out...

Thanks for your time!

Regards

P


Current thread: