Home page logo

snort logo Snort mailing list archives

Re: MySQL support for Snort 2.9.4
From: Kaya Saman <kayasaman () gmail com>
Date: Wed, 12 Dec 2012 03:26:08 +0000

On 12/11/2012 09:54 PM, Joel Esler wrote:

Doesn't sound like that was the problem. Looks like you have a larger problem. Traffic not being received or analyzed correctly. You said that all you were getting was icmp alerts, and that doesn't sound right (unless that's all you have)

*Joel Esler*
Senior Research Engineer, VRT
OpenSource Community Manager

Finally I got this working!!!! :-)

Basically all I needed to do was to add the paths for these in and take out all the other obsolete rules which weren't working:

include $RULE_PATH/decoder.rules
include $RULE_PATH/preprocessor.rules
include $RULE_PATH/sensitive-data.rules

Now I get alerts even!

The only issue is that Barnyard2 is now segfaulting when reading the Snort log files? :-( I keep getting "bus error" - which I've been having too much of lately!

Thanks for all the help!


LogMeIn Rescue: Anywhere, Anytime Remote support for IT. Free Trial
Remotely access PCs and mobile devices and provide instant support
Improve your efficiency, and focus on delivering more value-add services
Discover what IT Professionals Know. Rescue delivers
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:

Please visit http://blog.snort.org to stay current on all the latest Snort news!

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]