Snort mailing list archives

RE: Sensor logging at remote mysql db


From: "Michael Steele" <michaels () winsnort com>
Date: Mon, 8 Mar 2004 15:29:19 -0800

luis claudio silveira,

You can specify the IP and for the remote MySQL database in the snort.conf
file in the output database line. You will do exactly as a local database
but set the host= to the IP of Remote MySQL Database server. Make sure you
have a clear shot from the Snort sensor to the Remote MySQL server.

With the remote MySQL server running you should be able to telnet from the
Snort sensor to the remote MySQL server on port 3306 or 3307, and get a
response (MySQL version) from the remote MySQL database.

It always a plus when you can have a standalone remote MySQL database.

Kindest regards, 

The WINSNORT.com Management Team
-- 
Pick up your FREE Windows or UNIX Snort installation guides       
mailto:support () winsnort com
Website: http://www.winsnort.com
Snort: Open Source Network IDS - http://www.snort.org


-----Original Message-----
From: snort-users-admin () lists sourceforge net [mailto:snort-users-
admin () lists sourceforge net] On Behalf Of Luis Claudio R. da Silveira
Sent: Monday, March 08, 2004 12:47 PM
To: snort-users () lists sourceforge net
Subject: [Snort-users] Sensor logging at remote mysql db

Hi all,

I've configurated a  snort sensor in a linux box and a remote mysql
console
(ACID console) running on a Windows machine. I need to know if it's
possible
make the sensor machine send its output directly to this remote mysql db.
Is
it necessary to install mysql at sensor machine?? And considerations about
performance? Is it this choice better than setup mysql db running at the
same sensor machine? I've appreciate any help for my doubt.

thanks in advance,

luis claudio silveira





-------------------------------------------------------
This SF.Net email is sponsored by: IBM Linux Tutorials
Free Linux tutorial presented by Daniel Robbins, President and CEO of
GenToo technologies. Learn everything from fundamentals to system
administration.http://ads.osdn.com/?ad_id=1470&alloc_id=3638&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users





-------------------------------------------------------
This SF.Net email is sponsored by: IBM Linux Tutorials
Free Linux tutorial presented by Daniel Robbins, President and CEO of
GenToo technologies. Learn everything from fundamentals to system
administration.http://ads.osdn.com/?ad_id=1470&alloc_id=3638&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: