Snort mailing list archives

AW: How to Import Alert-Files into MySQL?


From: "Philipp" <ph.ilipp () gmx net>
Date: Thu, 16 Dec 2004 14:42:21 +0100

Sorry for posting twice and thanks for the answer, but there is a
misunderstanding. I have several alert files (from /var/log/snort) from some
experimental honeypots in amount of nearly 1GB. There I have only logged
them in text mode. For the Analysis now, I want them to import into a mysql
database on the analysis-box for statistical manner with tools like ACID or
the Honeynet Security Console. Some workaround was to replay (tcpreplay) the
binary-logs to a virtual interface and analyse them with snort again logging
to mysql, but all time-information is lost in this way. 
Again the question, is there a easy way to import them without writing a
perl-script?
I already found
http://archives.neohapsis.com/archives/snort/2001-03/0202.html, but it was
written for snort v1.6x and doesn't fit the newer versions. 
Regards,
        Philipp


-----Ursprüngliche Nachricht-----
Von: prabu333 () hotpop com [mailto:prabu333 () hotpop com] 
Gesendet: Donnerstag, 16. Dezember 2004 04:58
An: Philipp; Snort-users () lists sourceforge net
Betreff: Re: [Snort-users] How to Import Alert-Files into MySQL?

Read the README.database file present under the doc/ directory in your
snort source.It will guide you all the way.




-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now.
http://productguide.itmanagersjournal.com/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: