Snort mailing list archives

Installation of Snort Sensor


From: edmund.li () alcatel com hk
Date: Thu, 30 Oct 2003 16:20:31 +0800

Dear all, 

I have installed the snort server 2.0.2 on Redhat 9.0 with mysql, acid, 
snortcenter etc. It seems to be ok, (alert can be detected by scanning 
machine). Nowadays, I am starting the senor with another machine Redhat 
7.3, however I do not see any good topic about this. Any suggest for 
creating a sensor properly.

PS: (I installed snortcenter agent to Redhat 7.3) and it seems the senor 
can be controlled/watched by snort server 2.0.2 (with snortcenter) e.g, I 
can see the status of the sensor, however I can not see any alert 
detection from acid of snort server when I do the same scanning activities 
to the sensor.

What I did for the sensor
1) install mysql 4.0.16 without-server option ( I do not create any 
database at all), do I miss something, or I need to have a full 
installation with mysql server option ? 
2) install tcpdump.3.7.2
3) install  libcap-0.7.2
4) install snort-2.0.2
5) snortcenter-agent-v1.0-RC1

Base on the Snort Enterprise implementation guide, it seems sensor with 
send sql info to snort server for analysing. 

Edmund

Current thread: