Snort mailing list archives
RE: snort wont log to mysql database
From: "Semerjian, Ohanes" <Semerjian.Ohanes () wcom com au>
Date: Tue, 30 Apr 2002 07:41:28 +0800
from what u said it looks u have everything working okay, just check the home_net, external_net and also try to port scan using nmap rather only ping. One more thing is that in snort.conf u mentioned about the mysql, to make sure uncomment both lines to log event and also the alerts. Other than these to check u seams to have things working just need to be tuned. output database: log, mysql, user=root password=password dbname=db_name host=localhost output database: alert, mysql, user=root password=password dbname=db_name host=localhost Best Regards Ohanes Semerjian -----Original Message----- From: mnichols [mailto:mnichols () webentrada com] Sent: Monday, 29 April 2002 10:05 To: snort-users () lists sourceforge net Subject: [Snort-users] snort wont log to mysql database Good evening, I am unable to get snort to log to my mysql database. I'll be as specific as possible. I am using Slackware 8.0 2.2.19 kernel snort-1.8.6 and mysql-3.23.49. In snort.conf I have the plugin for mysql uncommented and I am using the root user for mysql and correct password. The root user has all privilages on the mysql database. I have snort compiled with mysql support and verified it with the configure script. When I start snort using snort -c /etc/snort.conf -i ppp0 -D snort starts and so does a mysql connection. I did check the sensor table and it shows the ip address of ppp0 which is a ppoe adsl connection. When I try a ping -l 1600 <ipaddress of ppp0> it does not log to either the mysql database or /var/log/snort/alert. Any suggestions I am truly stumped!! Thanks, -Marty _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- snort wont log to mysql database mnichols (Apr 28)
- <Possible follow-ups>
- RE: snort wont log to mysql database Semerjian, Ohanes (Apr 29)