Snort mailing list archives

Problem with Barnyard sending stuff to Mysql


From: Bouchra Badri <bouchra.badri () gmail com>
Date: Mon, 18 Feb 2013 21:07:12 +0000

Hello,
I hope you can help a first time user !

I have a problem, even though I have followed tutorials in both here :
http://nachum234.no-ip.org/category/security/snort/  and here :
http://www.nbs-system.com/blog/howto-idsips.html

I haven't been able to see any changes in the event database.

Sure the snort logs show as I type " snort" to launch it. Barnyard says it
works ( even though I have some warnings about not executing some Sql
commands (max cid where sid='2')) My sensors are localhost, localhost:eth0

and select count(*) from event; show ... Zero.

Yes the output in snort.conf is unified2
Yes the input in Barny is unified2 and the output is database mysql...


What did I miss please? I'm going crazy over this... 10 days I've been
trying to look for an answer online

Please help
------------------------------------------------------------------------------
The Go Parallel Website, sponsored by Intel - in partnership with Geeknet, 
is your hub for all things parallel software development, from weekly thought 
leadership blogs to news, videos, case studies, tutorials, tech docs, 
whitepapers, evaluation guides, and opinion stories. Check out the most 
recent posts - join the conversation now. http://goparallel.sourceforge.net/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: