Snort mailing list archives
Snort Test Error
From: "Mike Koponick" <mike () redhawk info>
Date: Thu, 2 Jan 2003 08:44:00 -0800
Hello all,
I hope everyone had a good New Year's.. now it's time to get some work done
;-)
I'm have an issue with SNORT. Over the holidays, the ACID database became
corupt somehow. So, I deleted the database, (I wasn't able to repait it) and
installed a new one, with the same files as the original.
Now, SNORT will not start. When testing it, I get the following output:
Testing Snort's ConfgurationInitializing Output Plugins!
Log directory = /var/log/snort
Initializing Network Interface eth1
WARNING: OpenPcap() device eth1 network lookup:
eth1: no IPv4 address assigned
--== Initializing Snort ==--
Decoding Ethernet on interface eth1
Initializing Preprocessors!
Initializing Plug-ins!
Parsing Rules file /etc/snort/snort.conf
+++++++++++++++++++++++++++++++++++++++++++++++++++
Initializing rule chains...
No arguments to frag2 directive, setting defaults to:
Fragment timeout: 60 seconds
Fragment memory cap: 4194304 bytes
Fragment min_ttl: 0
Fragment ttl_limit: 5
Fragment Problems: 0
Stream4 config:
Stateful inspection: ACTIVE
Session statistics: INACTIVE
Session timeout: 30 seconds
Session memory cap: 8388608 bytes
State alerts: INACTIVE
Evasion alerts: INACTIVE
Scan alerts: ACTIVE
Log Flushed Streams: INACTIVE
MinTTL: 1
TTL Limit: 5
Async Link: 0
*WARNING*: unknown preprocessor "stream4_reassemble, ports all", ignoring!
http_decode arguments:
Unicode decoding
IIS alternate Unicode decoding
IIS double encoding vuln
Flip backslash to slash
Include additional whitespace separators
Ports to decode http on: 80
rpc_decode arguments:
Ports to decode RPC on: 111 32771
telnet_decode arguments:
Ports to decode telnet on: 21 23 25 119
Using LOCAL time
Conversation Config:
KeepStats: 0
Conv Count: 32000
Timeout : 60
Alert Odd?: 1
Allowed IP Protocols:
Portscan2 config:
log: /var/log/snort/scan.log
scanners_max: 3200
targets_max: 5000
target_limit: 5
port_limit: 20
timeout: 60
WARNING => [Alert_FWsam](FWsamCheckIn) Could not connect to host
192.168.xx.xx. Will try later.
database: compiled support for ( mysql )
database: configured to use mysql
database: user = snort
database: password is set
database: database name = snort
database: host = localhost
database: sensor name = snort:eth1
database: sensor id = 2
database: schema version = 0
database: The underlying database seems to be running an older version of
the DB schema (current version=0, required minimum version= 106).
If you have an existing database with events logged by a previous
version of snort, this database must first be upgraded to the
latest
schema (see the snort-users mailing list archive or DB plugin
documention for details).
If migrating old data is not desired, merely create a new instance
of the snort database using the appropriate DB creation script
(e.g. create_mysql, create_postgresql, create_oracle,
create_mssql)
located in the contrib\ directory.
See the database documentation for cursory details
(doc/README.database).
and the URL to the most recent database plugin documentation.
Fatal Error, Quitting..
As far as I know, it's all the same files that I have been using in the
past.
Anyone have any ideas?
Thanks in advance,
Mike
-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Still having no luck getting stats when running CIS Scanner Salloum, Camile (Jan 02)
- Snort Test Error Mike Koponick (Jan 02)
- RE: Snort Test Error Michael Steele (Jan 02)
- RE: Snort Test Error Mike Koponick (Jan 02)
- RE: Snort Test Error Mike Koponick (Jan 02)
- RE: Snort Test Error Michael Steele (Jan 02)
- Snort Test Error Mike Koponick (Jan 02)
