Bluehost.com Web Hosting $6.95

[Snort-users] Syslogging question

This is a discussion on [Snort-users] Syslogging question within the Snort forums, part of the System Security and Security Related category; This is a multi-part message in MIME format. ------=_NextPart_000_0002_01C48919.1E9363A0 Content-Type: text/plain; charset="us-ascii" ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 08-23-2004
Steve
 
Posts: n/a
Default [Snort-users] Syslogging question

This is a multi-part message in MIME format.

------=_NextPart_000_0002_01C48919.1E9363A0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hi,

=20

New to the list, new to Linux, new to Snort, but trying hard!

=20

I have installed Smoothwall Express V2, and I'm having fun setting =
things up
and learning about all these things. But I'm stumped on one thing. I =
have
Kiwi Syslog Daemon running on a w2k3 box receiving syslog messages from
Smoothwall and Linux. I've changed syslog.conf to accomplish this, =
adding:

=20

*.* @192.168.0.60

=20

at the end. Now all my Smoothwall logs are happily arriving at Kiwi. But =
I'd
like to get Snort messages there too. I've changed snort.conf to =
uncomment
the line:

=20

output alert_syslog: LOG_AUTH LOG_ALERT

=20

but don't see any Snort messages in syslog. What else do I need to do? =
I've
trawled the web and archives but found nothing definitive, only lots of
people asking similar questions. Sorry if this has been covered before.

=20

While I'm here, there is one other syslog-related problem, although not =
with
Snort. After Smoothwall boot, it takes about 5 minutes for Kiwi to start
receiving anything from Smoothwall, even though Smoothwall in the =
meantime
logs messages.

=20

I have asked these questions on the Smoothwall list, but have received =
no
answers, so hoping someone here can help. Cheers.

=20

Steve

=20


------=_NextPart_000_0002_01C48919.1E9363A0
Content-Type: text/html;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html>

<head>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Dus-ascii">


<meta name=3DGenerator content=3D"Microsoft Word 10 (filtered)">

<style>
<!--
/* Font Definitions */
@font-face
{font-family:"Monotype Corsiva";
panose-1:3 1 1 1 1 2 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0cm;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman";}
a:link, span.MsoHyperlink
{color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{color:purple;
text-decoration:underline;}
p.MsoAutoSig, li.MsoAutoSig, div.MsoAutoSig
{margin:0cm;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman";}
span.EmailStyle17
{font-family:Arial;
color:windowtext;}
@page Section1
{size:21.0cm 842.0pt;
margin:72.0pt 89.85pt 72.0pt 89.85pt;}
div.Section1
{page:Section1;}
-->
</style>

</head>

<body lang=3DEN-US link=3Dblue vlink=3Dpurple>

<div class=3DSection1>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:
10.0pt;font-family:Arial'>Hi,</span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:
10.0pt;font-family:Arial'>&nbsp;</span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:
10.0pt;font-family:Arial'>New to the list, new to Linux, new to Snort, =
but
trying hard!</span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:
10.0pt;font-family:Arial'>&nbsp;</span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:
10.0pt;font-family:Arial'>I have installed S</span></font><font size=3D2
face=3DArial><span lang=3DEN-AU =
style=3D'font-size:10.0pt;font-family:Arial'>mo</span></font><font
size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:10.0pt;font-family:Arial'>othwall
Express V2, and I’m having fun setting things up and learning =
about all
these things. But I’m stumped on one thing. I have Kiwi Syslog =
Dae</span></font><font
size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:10.0pt;font-family:Arial'>mo</span></font><font
size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:10.0pt;font-family:Arial'>n
running on a w2k3 box receiving syslog messages from =
S</span></font><font
size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:10.0pt;font-family:Arial'>mo</span></font><font
size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:10.0pt;font-family:Arial'>othwall
and Linux. I’ve changed syslog.conf to accomplish this, =
adding:</span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:
10.0pt;font-family:Arial'>&nbsp;</span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:
10.0pt;font-family:Arial'>*.*&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb sp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs p;&nbsp;&nbsp;&nbsp;&nb=
sp; @192.168.0.60</span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:
10.0pt;font-family:Arial'>&nbsp;</span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:
10.0pt;font-family:Arial'>at the end. Now all my S</span></font><font =
size=3D2
face=3DArial><span lang=3DEN-AU =
style=3D'font-size:10.0pt;font-family:Arial'>mo</span></font><font
size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:10.0pt;font-family:Arial'>othwall
logs are happily arriving at Kiwi. But I’d like to get Snort =
messages
there too. I’ve changed snort.conf to uncomment the =
line:</span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:
10.0pt;font-family:Arial'>&nbsp;</span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:
10.0pt;font-family:Arial'>output alert_syslog: LOG_AUTH =
LOG_ALERT</span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:
10.0pt;font-family:Arial'>&nbsp;</span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:
10.0pt;font-family:Arial'>but don’t see any Snort messages in =
syslog. What
else do I need to do? I’ve trawled the web and archives but found =
nothing
definitive, only lots of people asking similar questions. Sorry if this =
has
been covered before.</span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:
10.0pt;font-family:Arial'>&nbsp;</span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:
10.0pt;font-family:Arial'>While I’m here, there is one other =
syslog-related
problem, although not with Snort. After S</span></font><font size=3D2 =
face=3DArial><span
lang=3DEN-AU =
style=3D'font-size:10.0pt;font-family:Arial'>mo</span></font><font
size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:10.0pt;font-family:Arial'>othwall
boot, it takes about 5 minutes for Kiwi to start receiving anything from =
S</span></font><font
size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:10.0pt;font-family:Arial'>mo</span></font><font
size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:10.0pt;font-family:Arial'>othwall,
even though S</span></font><font size=3D2 face=3DArial><span =
lang=3DEN-AU
style=3D'font-size:10.0pt;font-family:Arial'>mo</span></font><font =
size=3D2
face=3DArial><span lang=3DEN-AU =
style=3D'font-size:10.0pt;font-family:Arial'>othwall
in the meantime logs messages.</span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:
10.0pt;font-family:Arial'>&nbsp;</span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:
10.0pt;font-family:Arial'>I have asked these questions on the =
S</span></font><font
size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:10.0pt;font-family:Arial'>mo</span></font><font
size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:10.0pt;font-family:Arial'>othwall
list, but have received no answers, so hoping someone here can help. =
Cheers.</span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU =
style=3D'font-size:
10.0pt;font-family:Arial'>&nbsp;</span></font></p>

<p class=3DMsoAutoSig><b><font size=3D3 face=3D"Monotype Corsiva"><span
style=3D'font-size:12.0pt;font-family:"Monotype =
Corsiva";font-weight:bold'>Steve</span></font></b></p>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
lang=3DEN-AU
style=3D'font-size:12.0pt'>&nbsp;</span></font></p>

</div>

</body>

</html>

------=_NextPart_000_0002_01C48919.1E9363A0--



-------------------------------------------------------
SF.Net email is sponsored by Shop4tech.com-Lowest price on Blank Media
100pk Sonic DVD-R 4x for only $29 -100pk Sonic DVD+R for only $33
Save 50% off Retail on Ink & Toner - Free Shipping and Free Gift.
http://www.shop4tech.com/z/Inkjet_Cartridges/9_108_r285
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 04:10 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0