Snort mailing list archives
Snort logging and the home network
From: Bill McCarty <bmccarty () apu edu>
Date: Wed, 06 Mar 2002 12:00:46 -0800
I set up snort several weeks ago. I've tweaked the configuration and rules a few times and all has seemed well.
Today, I noticed that snort was no longer consistently producing packet logs in the directories named for IP addresses. Snort was logging some traffic, generally traffic pertaining to the home network. However, the most interesting traffic was not being logged. All the while, Snort continued posting alerts and logging everything in tcpdump format.
This looked like a problem with $HOME_NET. So, I inspected snort.conf but found no problem. Nevertheless, I restarted snort. However, this didn't change the situation.
I checked my startup script and found it did not include the -h option. So, as an experiment, I added one specifying the home net, and restarted snort. Bingo! I immediately got the logs that had stopped appearing.
Q: What is the relationship between the HOME_NET variable in snort.conf and the -h switch on the command line? I hope that, by better understanding this, I'll know why my configuration ceased working.
My log shows that I installed snort-mysql+flexresp-1.8.3-5snort on Sunday, March 3. My guess is that installing that version over snort-1.8.3-5snort, which was installed February 13, may have messed up something despite my replacing the original configuration file. Or, perhaps the behavior of the two program versions differs with respect to the handling of HOME_NET and the -h switch. More likely, I somehow goofed in replacing the configuration file, which looks good to me, but isn't....
Thanks! _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Snort logging and the home network Bill McCarty (Mar 06)
- Re: Snort logging and the home network Erek Adams (Mar 06)
- Re: Snort logging and the home network Bill McCarty (Mar 06)
- <Possible follow-ups>
- RE: Snort logging and the home network McCammon, Keith (Mar 06)
- Re: Snort logging and the home network Erek Adams (Mar 06)
