Snort mailing list archives

Re: Snort Install successful - Need a proper database


From: k vijay sai prashanth <vijaysaiprashanth () gmail com>
Date: Wed, 21 Nov 2012 03:27:53 +0530

Yes. I've made sure that snort is functioning properly and logging alerts
onto the snort.log files.

Barnyard2 is working too. When I enter the command which I got from an
installation guide:

/usr/local/bin/barnyard2 -c /etc/snort/barnyard2.conf -d /var/log/snort -f
snort.log -w /etc/snort/bylog.waldo -G /etc/snort/gen-msg.map -S
/etc/snort/sid-msg.map -C /etc/snort/classification.config

I get an output shown below:

 --== Initialization Complete ==--

  ______   -*> Barnyard2 <*-
 / ,,_  \  Version 2.1.9 (Build 263)
 |o"  )~|  By the SecurixLive.com Team: http://www.securixlive.com/about.php
 + '''' +  (C) Copyright 2008-2010 SecurixLive.

           Snort by Martin Roesch & The Snort Team:
http://www.snort.org/team.html
           (C) Copyright 1998-2007 Sourcefire Inc., et al.

Using waldo file '/etc/snort/bylog.waldo':
    spool directory = /var/log/snort
    spool filebase  = snort.log
    time_stamp      = 1353441428
    record_idx      = 25592
Opened spool file '/var/log/snort/snort.log.1353441428'


But I see that the mysql tables are still empty. Can someone tell me how to
have barnyard2 log events into the tables?
I've compiled barnyard2 with mysql. [./configure --with-mysql]

Regards,
Prashanth
------------------------------------------------------------------------------
Monitor your physical, virtual and cloud infrastructure from a single
web console. Get in-depth insight into apps, servers, databases, vmware,
SAP, cloud infrastructure, etc. Download 30-day Free Trial.
Pricing starts from $795 for 25 servers or applications!
http://p.sf.net/sfu/zoho_dev2dev_nov
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: