Snort mailing list archives

Re: error meant


From: Matt Kettler <mkettler () evi-inc com>
Date: Wed, 11 Jun 2003 19:55:21 -0400

At 07:11 PM 6/11/2003 -0500, msmythe () armada cl wrote:
BINGO!
as root i re-make "make install" and add the following path to the command:

snort -dev -l log -h xxx.xxx.xxx/24 -c
/home/msmythe/snort/snort-2.0.0/etc/snort.conf


Well, I said do one or the other.. but you did both.. in any event.. whatever snort.conf you want to use, pick one and stick with it.

it started initializing rule chains...., no argument to frag2, Stream4
config, htp_decode, rpc_decode, telnet_decode, etc, but sais the following
error messsage: database: mysql: Can´t connect..... but i think due i didn´t
finished to install mysql yet?

Yes, but you can fix that by disabling the mysql logging in the snort.conf and change the logging method to whatever you like.

For starters I'd just turn off any of the database output statements, and turn on:

output log_tcpdump: tcpdump.log

Either that or if you just want to test snort, run it without the -d option, it will run in console mode and dump alerts to the screen.




-------------------------------------------------------
This SF.NET email is sponsored by: eBay
Great deals on office technology -- on eBay now! Click here:
http://adfarm.mediaplex.com/ad/ck/711-11697-6916-5
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: