Snort mailing list archives
Re: MySQL support for Snort 2.9.4
From: waldo kitty <wkitty42 () windstream net>
Date: Wed, 12 Dec 2012 09:17:07 -0500
On 12/11/2012 17:02, Kaya Saman wrote:
On 12/11/2012 09:54 PM, Joel Esler wrote:On Dec 11, 2012, at 4:47 PM, Kaya Saman <kayasaman () gmail comUnknown MSG (145:3) Unknown MSG (145:4) Unknown MSG (145:5) Unknown MSG (145:6) Unknown MSG (2:1)That looks like your sig-msg.map is incorrect or something. Not sure where you are getting that output from.This output was from the: sid_changes.log file created by Pulled Pork.
so a pulledpork thing... not snort... that's different since they are maintained by different entities ;)
Doesn't sound like that was the problem. Looks like you have a larger problem. Traffic not being received or analyzed correctly. You said that all you were getting was icmp alerts, and that doesn't sound right (unless that's all you have)I think you misunderstood, basically I got a whole bunch of p2p ping errors in the older version. A few tcp messages but that was really only due to the fact that snort wasn't active long enough as it kept segfaulting with "bus error" as the output straight after being run. Had it been run for longer and not died instantaneously I'm sure it would have picked up quite a bit more traffic!! Even running: tcpdump -ttt -eni trunk0 displays a log of output when run for only a second or two.
what is your snort command line? ------------------------------------------------------------------------------ LogMeIn Rescue: Anywhere, Anytime Remote support for IT. Free Trial Remotely access PCs and mobile devices and provide instant support Improve your efficiency, and focus on delivering more value-add services Discover what IT Professionals Know. Rescue delivers http://p.sf.net/sfu/logmein_12329d2d _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- Re: MySQL support for Snort 2.9.4, (continued)
- Re: MySQL support for Snort 2.9.4 Jeremy Hoel (Dec 11)
- Re: MySQL support for Snort 2.9.4 Kaya Saman (Dec 11)
- Re: MySQL support for Snort 2.9.4 Joel Esler (Dec 11)
- Re: MySQL support for Snort 2.9.4 Jeremy Hoel (Dec 11)
- Re: MySQL support for Snort 2.9.4 Kaya Saman (Dec 11)
- Re: MySQL support for Snort 2.9.4 Jeremy Hoel (Dec 11)
- Re: MySQL support for Snort 2.9.4 Kaya Saman (Dec 11)
- Re: MySQL support for Snort 2.9.4 Jeremy Hoel (Dec 11)
- Re: MySQL support for Snort 2.9.4 waldo kitty (Dec 12)
- Re: MySQL support for Snort 2.9.4 Kaya Saman (Dec 12)
- Re: MySQL support for Snort 2.9.4 waldo kitty (Dec 12)
- Re: MySQL support for Snort 2.9.4 waldo kitty (Dec 12)
- Re: MySQL support for Snort 2.9.4 waldo kitty (Dec 12)
- Re: MySQL support for Snort 2.9.4 Joel Esler (Dec 11)
- Re: MySQL support for Snort 2.9.4 Joel Esler (Dec 11)
- Re: MySQL support for Snort 2.9.4 Joel Esler (Dec 11)
- Re: MySQL support for Snort 2.9.4 Joel Esler (Dec 11)
- Re: MySQL support for Snort 2.9.4 Kaya Saman (Dec 10)
- Re: MySQL support for Snort 2.9.4 Joel Esler (Dec 11)