Snort mailing list archives

Re: mysql error prevails...


From: AllowOverride <allowoverride () gmail com>
Date: Sat, 06 Oct 2012 14:16:26 -0700

thats a great idea, i have already virtualized an iso of security onion.
ill take a gander. nice of you to point me back to a huge config. thanks
--- Begin Message --- From: Doug Burks <doug.burks () gmail com>
Date: Sat, 6 Oct 2012 16:31:23 -0400
Hi AllowOverride,

If you're looking for working examples, you might consider downloading
Security Onion and see how we configure things there. The old version is
based on Ubuntu 10.04 and the new beta version is based on Ubuntu 12.04.

http://securityonion.blogspot.com

Hope that helps!

Thanks,
Doug

On Saturday, October 6, 2012, AllowOverride wrote:

eric, you are most certainly right, it is trivial, and i have already
connected locally per your suggestion
- no prob.

im starting to think it is what beeph said or.. a perm issues on the
dirs i created.

anyone please send me:

ls -al /etc/snort
ls -al /var/log/snort
ls -al /var/snort
ls -al /var/log/barnyard2
ls -al /usr/local/bin (include only pulledpork.pl, snort, and barnyard2
ls -al /etc/snort/etc/ or where ever you put your confs including top
level dir

actually please send me anything perm related with ls -al. that would
really help and give me insite as to what things should be
also - groups or perms snort:snort or snort:whatever listing
from /etc/passwd or /etc/groups with ID numbers - again so i can
compare. I don't believe man have defined it differently from the
defaults, these the entries i am concerned with. if you have elaborate
perms and set ups, this is not what i am scripting for, i am scripting
for a very simple non-inline IDS moded
snort/barnyard2/pulledpork/base/snortreport setup that anyone can load
and keep rules up to date... so on so forth...

remember, i simply followed the howtos enclosed:
i am using ubuntu server i386 12.04 LTS.

thanks! take a peek



-- 
Doug Burks
http://securityonion.blogspot.com

--- End Message ---
------------------------------------------------------------------------------
Don't let slow site performance ruin your business. Deploy New Relic APM
Deploy New Relic app performance management and know exactly
what is happening inside your Ruby, Python, PHP, Java, and .NET app
Try New Relic at no cost today and get our sweet Data Nerd shirt too!
http://p.sf.net/sfu/newrelic-dev2dev
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: