Snort mailing list archives

help snort


From: Quoc tuan Pham <phamtuan_luan () yahoo com vn>
Date: Sat, 16 Mar 2013 17:26:35 +0800 (SGT)

I using this command

#/usr/local/bin/snort -A console -q -u snort
-g snort -c /etc/snort/snort.conf -i eth0
the normal operation
test rules and reports
03/07-08:51:26.329372 [**] [1:10000001:1] ”test
snort co nguoi dang ping may tinh cua ban” [**] [Priority: 0] {ICMP}
192.168.1.102 -> 192.168.1.105
03/07-08:51:26.329453 [**] [1:10000001:1] ”test snort co
nguoi dang ping may tinh cua ban” [**] [Priority: 0] {ICMP} 192.168.1.105 ->
192.168.1.105

but not log into mysql and not on the base.

#/usr/local/bin/snort -q -u snort -g snort -c
/etc/snort/snort.conf -i eth0 &
#/usr/local/bin/barnyard2 -c /etc/snort/barnyard2.conf -d
/var/log/snort -f snort.log -w /etc/snort/bylog.waldo -G /etc/snort/gen-msg.map
-S /etc/snort/sid-msg.map -C /etc/snort/classification.config & 

then snort report

03/07-08:57:03.118541 [**] [1:10000001:1] Snort
Alert [1:10000001:0] [**] [Classification ID: (null)] [Priority ID: 0] {ICMP}
192.168.1.105 -> 192.168.1.102
03/07-08:57:03.118541
[**] [1:10000001:1] Snort Alert [1:10000001:0] [**] [Classification ID: (null)]
[Priority ID: 0] {ICMP} 192.168.1.105 -> 192.168.1.102
not last test rules and log into mysql and show up
base
-> So how to run the rules and how the command is?
-> and startup rules in case 2 is where?how to fix how to implement running rules?
------------------------------------------------------------------------------
Everyone hates slow websites. So do we.
Make your web apps faster with AppDynamics
Download AppDynamics Lite for free today:
http://p.sf.net/sfu/appdyn_d2d_mar
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: