Snort mailing list archives

Re: mysql support is not compiled into this build of snort


From: wkitty42 () windstream net
Date: Sat, 7 Apr 2018 15:20:34 -0400

On 04/07/2018 04:41 AM, 2014/2015 - Nsabimana Thierry wrote:
Could you please help me to overcome this issue?


1. please don't bold your lines in your posts... we can see and read them quite easily ;)

2. as Al noted, snort 2.6 is very old and out of date... snort no longer talks directly to the databases like it once did... there were too many situations that would cause snort to miss traffic (eg: the database was down)... snort would get hung up on the database stuff and simply miss traffic... so the database code was ripped out and snort only writes to its log files... now you use a tool like barnyard2 to take the data from snort's U2 log files and put it into the database... this separates the sniffing from the database insertions... then you can go from there doing your database thing with the alert data...


--
 NOTE: No off-list assistance is given without prior approval.
       *Please keep mailing list traffic on the list unless*
       *a signed and pre-paid contract is in effect with us.*
_______________________________________________
Snort-users mailing list
Snort-users () lists snort org
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette


Current thread: