Snort mailing list archives

Re: Snort's architecture


From: waldo kitty <wkitty42 () windstream net>
Date: Fri, 07 Sep 2012 20:44:21 -0400

On 9/7/2012 12:32, Victor Roemer wrote:
Just to clear it up. Database output was deprecated in 2.9.2 and removed in 2.9.3.

thanks for that, victor... i knew it was sometime in the 2.9 era but i just 
couldn't remember it and didn't feel like hunting thru my archives to determine 
exactly when it was or what version it was... my guess of 2.9.0.* was "slightly" 
off :lol:



~ Victor


On Fri, Sep 7, 2012 at 11:29 AM, waldo kitty <wkitty42 () windstream net
<mailto:wkitty42 () windstream net>> wrote:

    On 9/6/2012 21:29, dandantheitman wrote:
     > You could always argue that snort can also output to a database, as well as a
     > file or an alert,

    yeah, no... snort doesn't do database output any more... i forget which was the
    last version to support it but i suspect it was in the 2.8.* range... possibly
    one or two of the 2.9.0.* ones but nothing newer... for database output, you
    /have/ to run another tool to read the output files that snort does emit and
    have that tool do the output to the database...


------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: