Bluehost.com Web Hosting $6.95

[Snort-users] Trouble to log trace into database

This is a discussion on [Snort-users] Trouble to log trace into database within the Snort forums, part of the System Security and Security Related category; This is a multi-part message in MIME format. ------=_NextPart_000_001C_01C4C36F.51F71530 Content-Type: text/plain; charset="us-ascii" ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 11-06-2004
Juan
 
Posts: n/a
Default [Snort-users] Trouble to log trace into database

This is a multi-part message in MIME format.

------=_NextPart_000_001C_01C4C36F.51F71530
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: 7bit

Hi,

I have a trace file with some packets I am trying to analyze. I am trying to
load the trace into a mysql database but nothing gets logged.

My rules file looks like this:

# RULES

log tcp any any -> any any

log udp any any -> any any



And if I just run snort without loading from file, this rules logs every tcp
and udp header just fine into the database. Now when I run:

C:\Snort\bin>snort -r c:\trace.eth -c c:\Snort\etc\snort-mod.conf \

-l c:\Snort\log



I do not get any error but nothing gets logged to the database. See below
Can anyone give me a hint of what am I doing wrong?



Thanks,

J





================================================== ====================

database: compiled support for ( mysql odbc )

database: configured to use mysql

database: user = snort

database: password is set

database: database name = snort

database: host = localhost

database: sensor name = TRUSS:[reading from a file]

database: sensor id = 2

database: schema version = 106

database: using the "log" facility

2 Snort rules read...

2 Option Chains linked into 2 Chain Headers 0 Dynamic rules

++++++++++++++++++++++++++++++++++++++++++++++++++ +

+-----------------------[thresholding-config]---------------------------

+-------

| memory-cap : 1048576 bytes

+-----------------------[thresholding-global]---------------------------

+-------

| none

+-----------------------[thresholding-local]----------------------------

+-------

| none

+-----------------------[suppression]-----------------------------------

+-------

| none

----------------------------------------------------------------------------
---

Rule application order: ->activation->dynamic->alert->pass->log

--== Initialization Complete ==-- -*> Snort! <*- Version
2.2.0-ODBC-MySQL-FlexRESP-WIN32 (Build 30) By Martin Roesch
(roesch@sourcefire.com, www.snort.org)

1.7-WIN32 Port By Michael Davis (mike@datanerds.net,
www.datanerds.net/~mike)

1.8 - 2.x WIN32 Port By Chris Reid (chris.reid@codecraftconsultants.com)

Run time for packet processing was 0.501000 seconds
================================================== ==========================

Snort processed 84158 packets.

================================================== =========================

Breakdown by protocol:

TCP: 53451 (17.356%)

UDP: 28239 (37.124%)

ICMP: 13803 (1.561%)

ARP: 3240 (0.231%)

EAPOL: 0 (0.000%)

IPv6: 0 (0.000%)

IPX: 0 (0.000%)

OTHER: 8916 (1.008%)

DISCARD: 377709 (42.720%)

================================================== ==========================
===

Action Stats:

ALERTS: 0

LOGGED: 0

PASSED: 0

================================================== ==========================
===

Final Flow Statistics

,----[ FLOWCACHE STATS ]----------

Memcap: 10485760 Overhead Bytes 16400 used(%0.156403)/blocks (16400/1)
Overhead

blocks: 1 Could Hold: (0)

IPV4 count: 0 frees: 0 low_time: 0, high_time: 0, diff: 0h:00:00s

finds: 0 reversed: 0(%0.000000)

find_sucess: 0 find_fail: 0 percent_success: (%0.000000) new_flows: 0

database: Closing connection to database ""

Snort exiting






------=_NextPart_000_001C_01C4C36F.51F71530
Content-Type: text/html;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Dus-ascii">
<meta name=3DGenerator content=3D"Microsoft Word 11 (filtered medium)">
<style>
<!--
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin-top:0in;
margin-right:0in;
margin-bottom:6.0pt;
margin-left:0in;
text-align:justify;
font-size:12.0pt;
font-family:"Times New Roman";}
a:link, span.MsoHyperlink
{color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{color:purple;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:Arial;
color:windowtext;}
@page Section1
{size:8.5in 11.0in;
margin:1.0in 1.25in 1.0in 1.25in;}
div.Section1
{page:Section1;}
-->
</style>

</head>

<body lang=3DEN-US link=3Dblue vlink=3Dpurple>

<div class=3DSection1>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>Hi,<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>I have a trace file =
with
some packets I am trying to analyze. I am trying to load the trace into =
a mysql
database but nothing gets logged. <o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>My rules file looks =
like
this:<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'># =
RULES<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>log tcp any any =
-&gt; any
any<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>log udp any any =
-&gt; any
any<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>And if I just run =
snort
without loading from file, this rules logs every tcp and udp header just =
fine
into the database. Now when I run:<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>C:\Snort\bin&gt;snort -r c:\trace.eth
-c c:\Snort\etc\snort-mod.conf \<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; -l =
c:\Snort\log<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>I do not get any =
error but
nothing gets logged to the database. See below Can anyone give me a hint =
of
what am I doing wrong?<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>Thanks,<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>J<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D=3D=3D<o:p></=
o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>database: compiled =
support
for ( mysql odbc )<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>database: =
configured to use
mysql<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>database:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp ;&nbsp;&nbsp;&nbsp; =
user =3D
snort<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>database: password =
is set<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>database: database =
name =3D
snort<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>database:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp ;&nbsp;&nbsp;&nbsp; =
host =3D
localhost<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>database:&nbsp;&nbsp; sensor name =3D
TRUSS:[reading from a file]<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>database:&nbsp;&nbsp;&nbsp;&nbsp; sensor id =3D =
2<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>database: schema =
version =3D
106<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>database: using the
&quot;log&quot; facility<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>2 Snort rules =
read...<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>2 Option Chains =
linked into
2 Chain Headers 0 Dynamic rules<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>++++++++++++++++++++++++++++++++++++++++++++ +++++++<o:p></o:p></spa=
n></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>+-----------------------[thresholding-config]----------------------=
-----<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>+-------<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>| memory-cap : =
1048576 bytes<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>+-----------------------[thresholding-global]----------------------=
-----<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>+-------<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>| =
none<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>+-----------------------[thresholding-local]-----------------------=
-----<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>+-------<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>| =
none<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>+-----------------------[suppression]------------------------------=
-----<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>+-------<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>| =
none<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>-------------------------------------------------------------------=
------------<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>Rule application =
order:
-&gt;activation-&gt;dynamic-&gt;alert-&gt;pass-&gt;log<o:p></o:p></span><=
/font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; --=3D=3D Initialization
Complete =3D=3D-- -*&gt; Snort! &lt;*- Version =
2.2.0-ODBC-MySQL-FlexRESP-WIN32
(Build 30) By Martin Roesch (roesch@sourcefire.com, <a =
href=3D"www.snort.org">www.snort.org</a>)<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>1.7-WIN32 Port By =
Michael
Davis (mike@datanerds.net, <a =
href=3D"www.datanerds.net/~mike">www.datanerds.net/~mike</a>)<o:p></o:p><=
/span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>1.8 - 2.x WIN32 =
Port By
Chris Reid =
(chris.reid@codecraftconsultants.com)<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>Run time for packet
processing was 0.501000 seconds =
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>Snort processed =
84158
packets.<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>Breakdown by =
protocol:<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>&nbsp;&nbsp;&nbsp; =
TCP: 53451&nbsp;&nbsp;&nbsp;&nbsp; =
(17.356%)<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>&nbsp;&nbsp;&nbsp; =
UDP: 28239&nbsp;&nbsp;&nbsp;&nbsp; =
(37.124%)<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>&nbsp;&nbsp; ICMP: =
13803&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
(1.561%)<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>&nbsp;&nbsp;&nbsp; =
ARP: 3240&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
(0.231%)<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>&nbsp; EAPOL: =
0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;& nbsp; =
(0.000%)<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>&nbsp;&nbsp; IPv6: =
0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;& nbsp; =
(0.000%)<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>&nbsp;&nbsp;&nbsp; =
IPX: 0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;& nbsp; =
(0.000%)<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>&nbsp; OTHER: =
8916&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
(1.008%)<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>DISCARD: =
377709&nbsp;&nbsp;&nbsp;&nbsp;
(42.720%)<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>Action =
Stats:<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>ALERTS: =
0<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>LOGGED: =
0<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>PASSED: =
0<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'>=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>Final Flow =
Statistics<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>,----[ FLOWCACHE =
STATS
]----------<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>Memcap: 10485760 =
Overhead
Bytes 16400 used(%0.156403)/blocks (16400/1) =
Overhead<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>blocks: 1 Could =
Hold: (0)<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>IPV4 count: 0 =
frees: 0
low_time: 0, high_time: 0, diff: 0h:00:00s<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>&nbsp;&nbsp;&nbsp; =
finds: 0 reversed:
0(%0.000000)<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>&nbsp;&nbsp;&nbsp; =
find_sucess: 0
find_fail: 0 percent_success: (%0.000000) new_flows: =
0<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>database: Closing =
connection
to database &quot;&quot;<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier New"'>Snort =
exiting<o:p></o:p></span></font></p>

<p class=3DMsoNormal align=3Dleft =
style=3D'margin-bottom:0in;margin-bottom:.0001pt;
text-align:left;text-autospace:none'><font size=3D2 face=3D"Courier =
New"><span
style=3D'font-size:10.0pt;font-family:"Courier =
New"'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

</div>

</body>

</html>

------=_NextPart_000_001C_01C4C36F.51F71530--




-------------------------------------------------------
This SF.Net email is sponsored by:
Sybase ASE Linux Express Edition - download now for FREE
LinuxWorld Reader's Choice Award Winner for best database on Linux.
http://ads.osdn.com/?ad_id=5588&alloc_id=12065&op=click
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 04:01 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0