Snort mailing list archives

Re: simple mistake?


From: Erek Adams <erek () theadamsfamily net>
Date: Tue, 14 Aug 2001 06:10:30 -0700 (PDT)

On Tue, 14 Aug 2001, Chris Mason wrote:

I have snort 1.8 running on RH7.1, setup pretty much as standard, but I have
enabled the mysql loggin, provided a valid user and password (grant all on
snort_log.* to snort@localhost identified by 'password';)
restarted snort and I am getting entries in the /var/log/messages files and
in /var/log/snort/ but I am not getting any logging to the daatabase.

I tried "mysql -u snort -ppassword snort_log" and was able to execute select
statements. I don't know what to do next, any ideas?

Here's the nsort.conf entry:

output database: log, mysql, user=snort password=password dbname=snort_log
host=localhost

Keep in mind:  The first paramater after 'output database:' tells the DB
plugin what to pay attention to.  Change 'log' to 'alert' and you should be
good to go.

Chris Mason
masonc () masonc com
Box 340, The Valley, Anguilla, British West Indies

*sigh*  Has anyone ever told you 'Lucky Bastard'?  ;-)  Pardon me, I've got to
start my commute now...  *bleh*

-----
Erek Adams
Nifty-Type-Guy
TheAdamsFamily.Net


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: