Snort mailing list archives
snort will not log to mysql
From: Hans Steinraht <hsteinraht () openlot com>
Date: Tue, 3 Jun 2003 15:42:48 +0200
-- Hi, i'm just started playing with snort (version 2.0.0-3.1) on Linux Debian. When I add some rules like these in local.rules: #alert ip any any -> any any (msg:"Got an IP packet";) #alert tcp any any -> any any (msg:"Got an TCP packet";) #alert udp any any -> any any (msg:"Got an UDP packet";) #alert icmp any any -> any any (msg:"Got an ICMP packet";) all kind of data is inserted in mysql. When I remove the rules and do a scan to the firewall computer in our network I see entrys like "[**] [117:1:1] (spp_portscan2) Portscan detected ....." in my alert.log and in the portscan2.log, but nothing goes to mysql. The snort.conf file I have looks like this: output database: log, mysql, user=snort password=snort dbname=snort host=localhost preprocessor portscan2: scanners_max 256, targets_max 1024, target_limit 5, port_limit 20, timeout 60, log portscan2.log When I remove the option log from preprocessor portscan2 its going to log to scan.log, but still not to mysql. Does anyone has some advice for me on this. thanks, Hans ------------------------------------------------------- This SF.net email is sponsored by: eBay Get office equipment for less on eBay! http://adfarm.mediaplex.com/ad/ck/711-11697-6916-5 _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- snort will not log to mysql Hans Steinraht (Jun 03)
- Re: snort will not log to mysql Edin Dizdarevic (Jun 03)
- Re: snort will not log to mysql Hans Steinraht (Jun 04)
- Re: snort will not log to mysql Bamm Visscher (Jun 04)
- Re: snort will not log to mysql Hans Steinraht (Jun 05)
- <Possible follow-ups>
- Re: snort will not log to mysql Ron Shuck (Jun 05)
- Re: snort will not log to mysql Edin Dizdarevic (Jun 03)