This is a discussion on RE: [Snort-users] database output plugin sensor_name parameter and ACID strangeness within the Snort forums, part of the System Security and Security Related category; Hi, Try this: output database: alert, mysql, user=3Dsnort password=3Dfoo = dbname=3Dsnort host=3D10.99.99.99 sensor_name=3Dtest_ce0 ...
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
Hi, Try this: output database: alert, mysql, user=3Dsnort password=3Dfoo = dbname=3Dsnort host=3D10.99.99.99 sensor_name=3Dtest_ce0 Thanks. -----Original Message----- From: Muntner, Adam [mailto:Adam.Muntner@pegs.com]=20 Sent: Wednesday, April 28, 2004 8:33 AM To: snort-users@lists.sourceforge.net Subject: [Snort-users] database output plugin sensor_name parameter and = ACID strangeness I've been doing some experimenting using multiple senors and a single = console box, and have noticed the following behavior =20 Even if I set sensor_name in the output plugin list, it is not set in = the list of sensors... rather, it will say "0.0.0.0:ce1" (the interface = does not have an IP address and it is a gigabit nic interface named ce1) =20 If I go into the "sensor" table in the snort database, I can change the = hostname field to whatever I like. That works until I restart the = sensor... Unfortunately, it's only persistent until I restart the Snort = sensor. Then, a new interface is added to the list named "0.0.0.0:ce1" = and all the events end up attached to that sensor id. =20 Some advice would be appreciated! =20 My output line looks like: output database: alert, mysql, dbname=3Dsnort, sensor_name=3Dtest_ce0 = user=3Dsnort password=3Dfoo host=3D10.99.99.99 Adam Muntner, CISSP=20 =20 *****Confidentiality Notice*****************=20 This message contains confidential information and is intended only for the=20 individual named.If you are not the named addressee you should not disseminate,=20 distribute or copy this e-mail. Please=20 notify the sender immediately by e-mail if=20 you have received this e-mail by mistake and delete this e-mail from your system. ******************************************** ------------------------------------------------------- This SF.Net email is sponsored by: Oracle 10g Get certified on the hottest thing ever to hit the market... Oracle 10g. Take an Oracle 10g class now, and we'll give you the exam FREE. http://ads.osdn.com/?ad_id=3149&alloc_id=8166&op=click _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/...fo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.p...st=snort-users |