Snort mailing list archives
RE: RE: FAQ 10/100 Hubs Block Other Speed Traffic (was: RE: [Snort-users] External snort monitoring)
From: "James Friesen" <lucretia () telusplanet net>
Date: Fri, 10 Aug 2001 07:27:45 -0600
Hi folks.
More setup questions...I've almost got this working I just need a few more
pointers.
Currently MySQL seems to be working, setup and running ok, however it is not
logging data as it should be. It did, but doesn't anymore.
The only error (or discrepency) I see is that MyODBC is 'not found'. I
cannot find any references to ODBC or what is required, or what is MyODBC?
Would this break MySQL? Would this prevent logging to the snort database?
If not, then what would?
Secondly I have ACID logging and updating ok. Some of the parse errors
prior were due to misapplying paths with a trailing '\' which caused me tons
of grief (perhaps MS can make a note for the FAQ on this issue, causes very
strange and very hard to discover errors).
The current 'warning' I'm getting I'd like to solve any suggestions where to
look?
:Warning: Undefined offset: 12 in \wwwroot\acid\acid_db.inc on line 173
Current output from page...
Session Registered
Analysis Console for Intrusion Databases
URL: '/acid/acid_main.php' (refered by: '')
PARAMETERS: ''
CLIENT: Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.0)
SERVER: Microsoft-IIS/5.0
DATABASE TYPE: mysql
PHP VERSION: 4.0.6 DB ABSTRACTION VERSION:
Checking for DB abstraction lib in 'G:\SIDS\ADODB\adodb.inc.php'
Queried on : Fri August 10, 2001 07:23:05
Warning: Undefined offset: 12 in \wwwroot\acid\acid_db.inc on line 173
Database: snort@localhost (schema version: 0)
Time window: [2001-06-28 21:09:11] - [2001-07-08 20:11:33]
# of Sensors: 2
Unique Alerts: 9
Total Number of Alerts: 6643
Source IP addresses: 46
Dest. IP addresses: 9
Traffic Profile by Protocol
Warning: Undefined offset: 12 in F:\Inetpub\wwwroot\acid\acid_db.inc on line
173
TCP (1%)
UDP (0%)
ICMP (99%)
----------------------------------------------------------------------------
----
Alert Group (AG) maintenance
ACID v0.9.6b9 ( by Roman Danyliw as part of the AirCERT project )
Thanks in advance!
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Re: External snort monitoring, (continued)
- Re: External snort monitoring Erek Adams (Aug 08)
- Re: External snort monitoring Security @ Monster-Solutions.Net (Aug 08)
- RE: External snort monitoring swilcoxon (Aug 08)
- FAQ 10/100 Hubs Block Other Speed Traffic (was: RE: External snort monitoring) Dragos Ruiu (Aug 08)
- RE: FAQ 10/100 Hubs Block Other Speed Traffic (was: RE: External snort monitoring) Franki (Aug 08)
- RE: FAQ 10/100 Hubs Block Other Speed Traffic Erek Adams (Aug 08)
- RE: FAQ 10/100 Hubs Block Other Speed Traffic (was: RE: External snort monitoring) Rich Adamson (Aug 08)
- Re: FAQ 10/100 Hubs Block Other Speed Traffic (was: RE: External snort monitoring) Ramin Alidousti (Aug 08)
- RE: FAQ 10/100 Hubs Block Other Speed Traffic (was: RE: [Snort-users] External snort monitoring) Jason (Aug 08)
- RE: RE: FAQ 10/100 Hubs Block Other Speed Traffic (was: RE: [Snort-users] External snort monitoring) James Friesen (Aug 09)
- RE: RE: FAQ 10/100 Hubs Block Other Speed Traffic (was: RE: [Snort-users] External snort monitoring) James Friesen (Aug 10)
- Question? James Friesen (Aug 10)
- Re: Question? Jed Pickel (Aug 10)
- CODE RED III Mark Spieth (Aug 10)
- Re: CODE RED III Mike Baptiste (Aug 10)
- FAQ 10/100 Hubs Block Other Speed Traffic (was: RE: External snort monitoring) Dragos Ruiu (Aug 08)
- Re: External snort monitoring Erek Adams (Aug 08)
- Re: FAQ 10/100 Hubs Block Other Speed Traffic (was: RE: [Snort-users] External snort monitoring) Jim Hankins (Aug 08)
- Re: FAQ 10/100 Hubs Block Other Speed Traffic stefmit (Aug 08)
- Re: FAQ 10/100 Hubs Block Other Speed Traffic Murphy (Aug 08)
- Re: Re: FAQ 10/100 Hubs Block Other Speed Traffic Dragos Ruiu (Aug 09)
- Re: Re: FAQ 10/100 Hubs Block Other Speed Traffic Larry E. Smith Jr. (Aug 09)
- Re: Re: FAQ 10/100 Hubs Block Other Speed Traffic Jeff Ito (Aug 09)
