This is a discussion on [Snort-users] database output plugin sensor_name parameter and ACID strangeness within the Snort forums, part of the System Security and Security Related category; This is a multi-part message in MIME format. ------_=_NextPart_001_01C42CB8.976E7EA3 Content-Type: text/plain; charset="us-ascii&...
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
This is a multi-part message in MIME format.
------_=_NextPart_001_01C42CB8.976E7EA3 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable I've been doing some experimenting using multiple senors and a single console box, and have noticed the following behavior =20 Even if I set sensor_name in the output plugin list, it is not set in the list of sensors... rather, it will say "0.0.0.0:ce1" (the interface does not have an IP address and it is a gigabit nic interface named ce1) =20 If I go into the "sensor" table in the snort database, I can change the hostname field to whatever I like. That works until I restart the sensor... Unfortunately, it's only persistent until I restart the Snort sensor. Then, a new interface is added to the list named "0.0.0.0:ce1" and all the events end up attached to that sensor id. =20 Some advice would be appreciated! =20 My output line looks like: output database: alert, mysql, dbname=3Dsnort, sensor_name=3Dtest_ce0 user=3Dsnort password=3Dfoo host=3D10.99.99.99 Adam Muntner, CISSP=20 =20 ------_=_NextPart_001_01C42CB8.976E7EA3 Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <HTML><HEAD> <META http-equiv=3DContent-Type content=3D"text/html; = charset=3Dus-ascii"> <META content=3D"MSHTML 6.00.2800.1400" name=3DGENERATOR></HEAD> <BODY> <DIV><FONT face=3DArial size=3D2><SPAN class=3D881342300-28042004>I've = been doing some=20 experimenting using multiple senors and a single console box, and have = noticed=20 the following behavior</SPAN></FONT></DIV> <DIV><FONT face=3DArial size=3D2><SPAN=20 class=3D881342300-28042004></SPAN></FONT> </DIV> <DIV><FONT face=3DArial size=3D2><SPAN class=3D881342300-28042004>Even = if I set=20 sensor_name in the output plugin list, it is not set in the list of = sensors...=20 rather, it will say "0.0.0.0:ce1" (the interface does not have an IP = address and=20 it is a gigabit nic interface named ce1)</SPAN></FONT></DIV> <DIV><FONT face=3DArial size=3D2><SPAN=20 class=3D881342300-28042004></SPAN></FONT> </DIV> <DIV><FONT face=3DArial size=3D2><SPAN class=3D881342300-28042004>If I = go into the=20 "sensor" table in the snort database, I can change the hostname field to = whatever I like. That works until I restart the sensor... = Unfortunately,=20 it's only persistent until I restart the Snort sensor. Then, a new = interface is added to the list named "0.0.0.0:ce1" and all the events = end up=20 attached to that sensor id.</SPAN></FONT></DIV> <DIV><FONT face=3DArial size=3D2><SPAN=20 class=3D881342300-28042004></SPAN></FONT> </DIV> <DIV><FONT face=3DArial size=3D2><SPAN class=3D881342300-28042004>Some = advice would be=20 appreciated!</SPAN></FONT></DIV> <DIV><FONT face=3DArial size=3D2><SPAN=20 class=3D881342300-28042004></SPAN></FONT> </DIV> <DIV><FONT face=3DArial size=3D2><SPAN class=3D881342300-28042004>My = output line looks=20 like:</SPAN></FONT></DIV> <DIV><FONT face=3DArial size=3D2><SPAN class=3D881342300-28042004>output = database:=20 alert, mysql, dbname=3Dsnort, sensor_name=3Dtest_ce0 = user=3Dsnort password=3Dfoo=20 host=3D10.99.99.99<BR></SPAN></FONT></DIV> <P class=3DMsoNormal align=3Dleft><SPAN=20 style=3D"FONT-SIZE: 10pt; FONT-FAMILY: Arial">Adam Muntner,=20 CISSP </SPAN><BR></P> <DIV> </DIV></BODY></HTML> ------_=_NextPart_001_01C42CB8.976E7EA3-- ------------------------------------------------------- This SF.Net email is sponsored by: Oracle 10g Get certified on the hottest thing ever to hit the market... Oracle 10g. Take an Oracle 10g class now, and we'll give you the exam FREE. http://ads.osdn.com/?ad_id=3149&alloc_id=8166&op=click _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/...fo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.p...st=snort-users |
![]() |
| Thread Tools | |
| Display Modes | |
|
|