Snort mailing list archives

Re: Acid shows sensors as 0


From: Kevin Johnson <kjohnson () secureideas net>
Date: Tue, 23 Nov 2004 15:10:26 -0500

On Tue, 2004-11-23 at 14:50, Gentian Hila wrote:
Does it mean that is connecting ok ? I guess so ?
What table is that snort saves the data ?

Thank you very much :)

Hi-

Yes that would mean that Snort is connecting, now we need to figure out
whether it is actually alerting to the database.

What is the line that you have set up in snort.conf to alert?

i.e. 
output database: log, mysql, user=username password=passwd
dbname=snort_log host=localhost

Is this uncommented?  Also how many rows are in your event table?

Kevin
-------------------
BASE Project Lead
http://sourceforge.net/projects/secureideas
http://base.secureideas.net
The next step in IDS analysis!

Attachment: signature.asc
Description: This is a digitally signed message part


Current thread: