This is a discussion on [Snort-users] Snort not logging to database within the Snort forums, part of the System Security and Security Related category; I installed Snort 2.0.2, Apache 2.0.47, PHP 4.3.1, Mysql 4.0.12 and Acid=...
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
I installed Snort 2.0.2, Apache 2.0.47, PHP 4.3.1, Mysql 4.0.12 and Acid=20
0.9.6b23 from source onto my linux box running Slackware 8.1 with kernel=20 2.4.18 following instructions in a Snort Installation Manual by Patrick=20 Harper. I had already been using earlier versions of Apache, PHP and Mys= ql=20 on this box. The install went fine and all programs are operational but,= =20 Snort is not logging to the database.=20 I have a firewall (Shorewall) masquerading for subnet 192.168.0.0/24 on p= pp0=20 (a pppoe/dsl connection). Eth0 is my internal iface and Eth1 connects to = the=20 modem. I noticed in the snort startup script that snort would initialize = and=20 listen on eth0. Is that right? Or will the firewall drop packets before S= nort=20 can see them? I read the manual and searched archives but haven't solved the problem. Excerpt from snort.conf var HOME_NET 192.168.0.0/24 var EXTERNAL_NET any output database: log, mysql, dbname=3Dsnort user=3Dsnortusr host=3Dlocalh= ost /=20 password=3Dxyz Bruce ------------------------------------------------------- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/...fo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.p...st=snort-users |
![]() |
| Thread Tools | |
| Display Modes | |
|
|