Snort mailing list archives

Portscan - remote mysql and Acid ??


From: "Jeffries, Michael MJ" <Michael.Jeffries () standardbank co za>
Date: Fri, 17 Dec 2004 12:04:52 +0200


Hi there,

I have added the following line in my snort.conf file

preprocessor portscan: any 5 7 /var/log/portscan.log

So I am now logging portscan type messages to /var/log/portscan.log, BUT the
issue is, I have a mysql database server and the ACID consol on a different
machine, How do I get my portscan to feed into this remote database instead
of this current flatfile so that ACID on my management station can read it
from a DB?

All other messages gets logged perfectly to the database, besides these
portscans.

Thanks a ton
Mike

__________________________________________________________________________________________________________________________________

Standard Bank Disclaimer and Confidentiality Note

This e-mail, its attachments and any rights attaching hereto are, unless the context clearly indicates otherwise, the 
property of Standard Bank Group Limited and/or its subsidiaries ("the Group"). It is confidential, private and intended 
for the addressee only. 

Should you not be the addressee and receive this e-mail by mistake, kindly notify the sender, and delete this e-mail, 
immediately and do not disclose or use same in any manner whatsoever. 

Views and opinions expressed in this e-mail are those of the sender unless clearly stated as those of the Group. The 
Group accepts no liability whatsoever for any loss or damages whatsoever and howsoever incurred, or suffered, 
resulting, or arising, from the use of this email or its attachments.

The Group does not warrant the integrity of this e-mail nor that it is free of errors, viruses, interception or 
interference. 

Licensed divisions of the Standard Bank Group are authorised financial services providers in terms of the Financial 
Advisory and Intermediary Services Act, No 37 of 2002 (FAIS).

For information about the Standard Bank Group Limited visit our website http://www.standardbank.co.za
___________________________________________________________________________________________________________________________________

Current thread: