This is a discussion on [Snort-users] Syslogging question within the Snort forums, part of the System Security and Security Related category; This is a multi-part message in MIME format. ------=_NextPart_000_0002_01C48919.1E9363A0 Content-Type: text/plain; charset="us-ascii" ...
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
This is a multi-part message in MIME format.
------=_NextPart_000_0002_01C48919.1E9363A0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable Hi, =20 New to the list, new to Linux, new to Snort, but trying hard! =20 I have installed Smoothwall Express V2, and I'm having fun setting = things up and learning about all these things. But I'm stumped on one thing. I = have Kiwi Syslog Daemon running on a w2k3 box receiving syslog messages from Smoothwall and Linux. I've changed syslog.conf to accomplish this, = adding: =20 *.* @192.168.0.60 =20 at the end. Now all my Smoothwall logs are happily arriving at Kiwi. But = I'd like to get Snort messages there too. I've changed snort.conf to = uncomment the line: =20 output alert_syslog: LOG_AUTH LOG_ALERT =20 but don't see any Snort messages in syslog. What else do I need to do? = I've trawled the web and archives but found nothing definitive, only lots of people asking similar questions. Sorry if this has been covered before. =20 While I'm here, there is one other syslog-related problem, although not = with Snort. After Smoothwall boot, it takes about 5 minutes for Kiwi to start receiving anything from Smoothwall, even though Smoothwall in the = meantime logs messages. =20 I have asked these questions on the Smoothwall list, but have received = no answers, so hoping someone here can help. Cheers. =20 Steve =20 ------=_NextPart_000_0002_01C48919.1E9363A0 Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable <html> <head> <META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; = charset=3Dus-ascii"> <meta name=3DGenerator content=3D"Microsoft Word 10 (filtered)"> <style> <!-- /* Font Definitions */ @font-face {font-family:"Monotype Corsiva"; panose-1:3 1 1 1 1 2 1 1 1 1;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0cm; margin-bottom:.0001pt; font-size:12.0pt; font-family:"Times New Roman";} a:link, span.MsoHyperlink {color:blue; text-decoration:underline;} a:visited, span.MsoHyperlinkFollowed {color:purple; text-decoration:underline;} p.MsoAutoSig, li.MsoAutoSig, div.MsoAutoSig {margin:0cm; margin-bottom:.0001pt; font-size:12.0pt; font-family:"Times New Roman";} span.EmailStyle17 {font-family:Arial; color:windowtext;} @page Section1 {size:21.0cm 842.0pt; margin:72.0pt 89.85pt 72.0pt 89.85pt;} div.Section1 {page:Section1;} --> </style> </head> <body lang=3DEN-US link=3Dblue vlink=3Dpurple> <div class=3DSection1> <p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size: 10.0pt;font-family:Arial'>Hi,</span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size: 10.0pt;font-family:Arial'> </span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size: 10.0pt;font-family:Arial'>New to the list, new to Linux, new to Snort, = but trying hard!</span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size: 10.0pt;font-family:Arial'> </span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size: 10.0pt;font-family:Arial'>I have installed S</span></font><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size:10.0pt;font-family:Arial'>mo</span></font><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size:10.0pt;font-family:Arial'>othwall Express V2, and I’m having fun setting things up and learning = about all these things. But I’m stumped on one thing. I have Kiwi Syslog = Dae</span></font><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size:10.0pt;font-family:Arial'>mo</span></font><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size:10.0pt;font-family:Arial'>n running on a w2k3 box receiving syslog messages from = S</span></font><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size:10.0pt;font-family:Arial'>mo</span></font><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size:10.0pt;font-family:Arial'>othwall and Linux. I’ve changed syslog.conf to accomplish this, = adding:</span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size: 10.0pt;font-family:Arial'> </span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size: 10.0pt;font-family:Arial'>*.* &nb sp; &n= bsp; &nbs p; &nb= sp; @192.168.0.60</span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size: 10.0pt;font-family:Arial'> </span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size: 10.0pt;font-family:Arial'>at the end. Now all my S</span></font><font = size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size:10.0pt;font-family:Arial'>mo</span></font><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size:10.0pt;font-family:Arial'>othwall logs are happily arriving at Kiwi. But I’d like to get Snort = messages there too. I’ve changed snort.conf to uncomment the = line:</span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size: 10.0pt;font-family:Arial'> </span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size: 10.0pt;font-family:Arial'>output alert_syslog: LOG_AUTH = LOG_ALERT</span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size: 10.0pt;font-family:Arial'> </span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size: 10.0pt;font-family:Arial'>but don’t see any Snort messages in = syslog. What else do I need to do? I’ve trawled the web and archives but found = nothing definitive, only lots of people asking similar questions. Sorry if this = has been covered before.</span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size: 10.0pt;font-family:Arial'> </span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size: 10.0pt;font-family:Arial'>While I’m here, there is one other = syslog-related problem, although not with Snort. After S</span></font><font size=3D2 = face=3DArial><span lang=3DEN-AU = style=3D'font-size:10.0pt;font-family:Arial'>mo</span></font><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size:10.0pt;font-family:Arial'>othwall boot, it takes about 5 minutes for Kiwi to start receiving anything from = S</span></font><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size:10.0pt;font-family:Arial'>mo</span></font><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size:10.0pt;font-family:Arial'>othwall, even though S</span></font><font size=3D2 face=3DArial><span = lang=3DEN-AU style=3D'font-size:10.0pt;font-family:Arial'>mo</span></font><font = size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size:10.0pt;font-family:Arial'>othwall in the meantime logs messages.</span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size: 10.0pt;font-family:Arial'> </span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size: 10.0pt;font-family:Arial'>I have asked these questions on the = S</span></font><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size:10.0pt;font-family:Arial'>mo</span></font><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size:10.0pt;font-family:Arial'>othwall list, but have received no answers, so hoping someone here can help. = Cheers.</span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span lang=3DEN-AU = style=3D'font-size: 10.0pt;font-family:Arial'> </span></font></p> <p class=3DMsoAutoSig><b><font size=3D3 face=3D"Monotype Corsiva"><span style=3D'font-size:12.0pt;font-family:"Monotype = Corsiva";font-weight:bold'>Steve</span></font></b></p> <p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span = lang=3DEN-AU style=3D'font-size:12.0pt'> </span></font></p> </div> </body> </html> ------=_NextPart_000_0002_01C48919.1E9363A0-- ------------------------------------------------------- SF.Net email is sponsored by Shop4tech.com-Lowest price on Blank Media 100pk Sonic DVD-R 4x for only $29 -100pk Sonic DVD+R for only $33 Save 50% off Retail on Ink & Toner - Free Shipping and Free Gift. http://www.shop4tech.com/z/Inkjet_Cartridges/9_108_r285 _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/...fo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.p...st=snort-users |