Snort mailing list archives

RE: Mysql is collecting data from snort, Acid won't display it.


From: "Michael Steele" <michaels () winsnort com>
Date: Sat, 14 Feb 2004 15:27:48 -0800

Are you SURE snort is running? Are you SURE there are even any alerts in the
alert.ids file. Are you SURE there are no error messages in your error log
depicting what might be wrong?

Kindest regards, 

The WINSNORT.com Management Team
-- 
Pick up your FREE Windows or UNIX Snort installation guides       
mailto:support () winsnort com
Website: http://www.winsnort.com
Snort: Open Source Network IDS - http://www.snort.org


-----Original Message-----
From: snort-users-admin () lists sourceforge net [mailto:snort-users-
admin () lists sourceforge net] On Behalf Of Wally Bedford
Sent: Saturday, February 14, 2004 2:58 PM
To: snort-users () lists sourceforge net
Subject: [Snort-users] Mysql is collecting data from snort, Acid won't
display it.

I have a sensor with snort-2.0.0p1-mysql going to an acid console
running mysql-server-3.23.57p1 and Acid version 0.9.6b23.

Acid opens without an error, and I went through the setup databases
page.  All was fine.  I can see all sorts of alerts in the
acid_maintenance.php page, which shows...

Alert Information Cache
Total Events: 6256   Cached Events: 0

But no alerts show up.  The acid_main.php page shows...

Added 0 alert(s) to the Alert cache

Queried on : Fri February 13, 2004 16:16:30
Database: snort@localhost    (schema version: 106)
Time window: no alerts detected


My configuration is pretty vanilla, just basic changes to the
acid_conf.php file to reflect the local setup.

Any ideas on where to look would sure be welcome,

Wally




-------------------------------------------------------
SF.Net is sponsored by: Speed Start Your Linux Apps Now.
Build and deploy apps & Web services for Linux with
a free DVD software kit from IBM. Click Now!
http://ads.osdn.com/?ad_id=1356&alloc_id=3438&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users





-------------------------------------------------------
SF.Net is sponsored by: Speed Start Your Linux Apps Now.
Build and deploy apps & Web services for Linux with
a free DVD software kit from IBM. Click Now!
http://ads.osdn.com/?ad_id=1356&alloc_id=3438&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: