|
Home > Archive > Snort > September 2004 > [Snort-users] An acid problem.
You are viewing an archived Text-only version of the thread.
To view this thread in it's original format and/or if you want to reply to
this thread please [click here]
| Author |
[Snort-users] An acid problem.
|
|
|
| This is a multi-part message in MIME format.
------=_NextPart_000_002D_01C4A240.2899A0E0
Content-Type: text/plain;
charset="big5"
Content-Transfer-Encoding: quoted-printable
hi,
i installed snort, mysql, acid by ports on a freebsd box.=20
When i try to display Alert Listing: 15 Last Alerts, there is nothing =
show on the
screen. as following. What's the problem?
ACID
Alert Listing: 15 Last Alerts Home
Search | AG Maintenance
[ Back ]
Added 0 alert(s) to the Alert cache
Queried DB on : Fri September 24, 2004 10:22:20 Meta Criteria any
IP Criteria any
Layer 4 Criteria none
Payload Criteria any
Displaying 15 Last Alerts
Thanks.
------=_NextPart_000_002D_01C4A240.2899A0E0
Content-Type: text/html;
charset="big5"
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; charset=3Dbig5">
<META content=3D"MSHTML 6.00.2800.1458" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV>hi,</DIV>
<DIV> </DIV>
<DIV><FONT size=3D2><FONT size=3D3>i installed snort, mysql, acid by =
ports on a=20
freebsd box.</FONT> </FONT></DIV>
<DIV>When i try to display Alert Listing: 15 Last Alerts, there is =
nothing show=20
on the<BR>screen. as following. What's the=20
problem?<BR><BR> =
ACID<BR> =20
Alert Listing: 15 Last Alerts=20
Home<BR>  =
;=20
Search | AG=20
Maintenance<BR><BR> [ Back ]<BR><BR>Added =
0=20
alert(s) to the Alert cache<BR> Queried DB on : Fri September 24, =
2004=20
10:22:20 Meta Criteria =20
any<BR> =
=20
IP Criteria =20
any<BR> =
=20
Layer 4 Criteria =20
none<BR>  =
; =20
Payload Criteria any<BR><BR><BR><BR><BR>Displaying 15 =
Last=20
Alerts<BR><BR><FONT size=3D2>Thanks.</FONT></DIV>
<DIV><FONT size=3D2></FONT> </DIV></BODY></HTML>
------=_NextPart_000_002D_01C4A240.2899A0E0--
-------------------------------------------------------
This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170
Project Admins to receive an Apple iPod Mini FREE for your judgement on
who ports your project to Linux PPC the best. Sponsored by IBM.
Deadline: Sept. 24. Go here: http://sf.net/ppc_contest.php
________________________________________
_______
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists...nfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf....ist=snort-users
| |
| Gould, Scott 2004-09-24, 2:46 am |
| This is a multi-part message in MIME format.
------_=_NextPart_001_01C4A208.A27D7072
Content-Type: text/plain;
charset="US-ASCII"
Content-Transfer-Encoding: quoted-printable
My 1st thought would be to check your snort.conf file for the
appropriate output plug-in configuration. You need to tell snort to log
to your mysql db, via an output db plug-in line in your snort.conf
file..
=20
The documentation at snort.org and the snort.conf file give examples of
database output logging.
=20
This, is however a method that may not be able to keep up with high
bandwidth. You may want to consider a flow like this if you have high
bandwidth pipes your monitoring:
=20
Snort logs to binary log file
Barnyard monitors binary log file, and does inserts into mysql db
=20
Lots of information about barnyard can be found in the various setup
docs available at snort.org, and by searching the archives of this list.
=20
My best advice, only being at this for a year or so myself, is to start
simple (which your doing:-)), get your current setup working, then look
to tune performance down the road.
=20
Hope this helps.
=20
Scott Gould, MCP
Senior Network & Systems Analyst
Gynecologic Oncology Group=20
Statistical & Data Center
sgould@gogstats.org
716-845-5702
________________________________
From: snort-users-admin@lists.sourceforge.net
[mailto:snort-users-admin@lists.sourceforge.net] On Behalf Of kinux
Sent: Friday, September 24, 2004 2:10 AM
To: snort-users@lists.sourceforge.net
Subject: [Snort-users] An acid problem.
=20
hi,
=20
i installed snort, mysql, acid by ports on a freebsd box.=20
When i try to display Alert Listing: 15 Last Alerts, there is nothing
show on the
screen. as following. What's the problem?
ACID
Alert Listing: 15 Last Alerts Home
Search | AG Maintenance
[ Back ]
Added 0 alert(s) to the Alert cache
Queried DB on : Fri September 24, 2004 10:22:20 Meta Criteria any
IP Criteria any
Layer 4 Criteria none
Payload Criteria any
Displaying 15 Last Alerts
Thanks.
=20
------_=_NextPart_001_01C4A208.A27D7072
Content-Type: text/html;
charset="US-ASCII"
Content-Transfer-Encoding: quoted-printable
<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:st1=3D"urn:schemas-microsoft-com:office:smarttags" =
xmlns=3D"http://www.w3.org/TR/REC-html40"
xmlns:ns0=3D"urn:schemas-microsoft-com:office:smarttags">
<head>
<meta http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dus-ascii">
<meta name=3DGenerator content=3D"Microsoft Word 11 (filtered medium)">
<!--[if !mso]>
<style>
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
..shape {behavior:url(#default#VML);}
</style>
<![endif]--><o:SmartTagType
namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags" =
name=3D"PlaceType"/>
<o:SmartTagType =
namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
name=3D"PlaceName"/>
<o:SmartTagType =
namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
name=3D"place"/>
<o:SmartTagType =
namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
name=3D"PersonName"/>
<!--[if !mso]>
<style>
st1\:*{behavior:url(#default#ieooui) }
</style>
<![endif]-->
<style>
<!--
/* Font Definitions */
@font-face
{font-family:Wingdings;
panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
{font-family:PMingLiU;
panose-1:2 1 6 1 0 1 1 1 1 1;}
@font-face
{font-family:Tahoma;
panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
{font-family:"\@PMingLiU";
panose-1:0 0 0 0 0 0 0 0 0 0;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:PMingLiU;}
a:link, span.MsoHyperlink
{color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{color:purple;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-reply;
font-family:Arial;
color:navy;}
@page Section1
{size:8.5in 11.0in;
margin:1.0in 1.25in 1.0in 1.25in;}
div.Section1
{page:Section1;}
-->
</style>
<!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body bgcolor=3Dwhite lang=3DEN-US link=3Dblue vlink=3Dpurple>
<div class=3DSection1>
<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>My 1<sup>st</sup> thought would be =
to check
your snort.conf file for the appropriate output plug-in =
configuration.
You need to tell snort to log to your mysql db, via an output db plug-in =
line
in your snort.conf file..<o:p></o:p></span></font></p>
<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'><o:p> </o:p></span></font></p>
<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>The documentation at snort.org and =
the
snort.conf file give examples of database output =
logging.<o:p></o:p></span></font></p>
<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'><o:p> </o:p></span></font></p>
<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>This, is however a method that may =
not be
able to keep up with high bandwidth. You may want to consider a =
flow like
this if you have high bandwidth pipes your =
monitoring:<o:p></o:p></span></font></p>
<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'><o:p> </o:p></span></font></p>
<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>Snort logs to binary log =
file<o:p></o:p></span></font></p>
<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>Barnyard monitors binary log file, =
and does
inserts into mysql db<o:p></o:p></span></font></p>
<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'><o:p> </o:p></span></font></p>
<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>Lots of information about barnyard =
can be
found in the various setup docs available at snort.org, and by searching =
the
archives of this list.<o:p></o:p></span></font></p>
<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'><o:p> </o:p></span></font></p>
<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>My best advice, only being at this =
for a
year or so myself, is to start simple (which your =
doing</span></font><font
size=3D2 color=3Dnavy face=3DWingdings><span =
style=3D'font-size:10.0pt;font-family:
Wingdings;color:navy'>J</span></font><font size=3D2 color=3Dnavy =
face=3DArial><span
style=3D'font-size:10.0pt;font-family:Arial;color:navy'> ), get your =
current setup
working, then look to tune performance down the =
road.<o:p></o:p></span></font></p>
<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'><o:p> </o:p></span></font></p>
<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>Hope this =
helps.<o:p></o:p></span></font></p>
<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'><o:p> </o:p></span></font></p>
<div>
<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>Scott Gould, MCP</span></font><font
color=3Dnavy><span style=3D'color:navy'><o:p></o:p></span></font></p>
<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>Senior Network & Systems =
Analyst</span></font><font
color=3Dnavy><span style=3D'color:navy'><o:p></o:p></span></font></p>
<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>Gynecologic Oncology =
Group </span></font><font
color=3Dnavy><span style=3D'color:navy'><o:p></o:p></span></font></p>
<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>Statistical & =
</span></font><font
size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;font-family:Arial'><ns0:place
w:insAuthor=3D"gould" w:insDate=3D"2004-09-24T03:25:00Z" =
w:endInsAuthor=3D"gould"
w:endInsDate=3D"2004-09-24T03:25:00Z"><ns0:PlaceName =
w:insAuthor=3D"gould"
w:insDate=3D"2004-09-24T03:25:00Z" w:endInsAuthor=3D"gould"
w:endInsDate=3D"2004-09-24T03:25:00Z"><st1:place =
w:st=3D"on"><st1:PlaceName
w:st=3D"on"><font color=3Dnavy><span =
style=3D'color:navy'>Data</span></font></st1:PlaceName></ns0:PlaceName></=
st1:place><font
color=3Dnavy><span style=3D'color:navy'> </span></font><ns0:PlaceType
w:insAuthor=3D"gould" w:insDate=3D"2004-09-24T03:25:00Z" =
w:endInsAuthor=3D"gould"
w:endInsDate=3D"2004-09-24T03:25:00Z"><st1:PlaceType w:st=3D"on"><font
color=3Dnavy><span =
style=3D'color:navy'>Center</span></font></st1:PlaceType></ns0:PlaceType>=
</ns0:place></span></font><font
color=3Dnavy><span style=3D'color:navy'><o:p></o:p></span></font></p>
<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'><ns0:place w:insAuthor=3D"gould" =
w:insDate=3D"2004-09-24T03:25:00Z"
w:endInsAuthor=3D"gould" =
w:endInsDate=3D"2004-09-24T03:25:00Z"><ns0:PlaceType
w:insAuthor=3D"gould" w:insDate=3D"2004-09-24T03:25:00Z" =
w:endInsAuthor=3D"gould"
w:endInsDate=3D"2004-09-24T03:25:00Z"><font color=3Dnavy><span =
style=3D'color:navy'>sgould@gogstats.org</span></font></ns0:PlaceType></n=
s0:place></span></font><font
color=3Dnavy><span style=3D'color:navy'><o:p></o:p></span></font></p>
<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'><ns0:place w:insAuthor=3D"gould" =
w:insDate=3D"2004-09-24T03:25:00Z"
w:endInsAuthor=3D"gould" =
w:endInsDate=3D"2004-09-24T03:25:00Z"><ns0:PlaceType
w:insAuthor=3D"gould" w:insDate=3D"2004-09-24T03:25:00Z" =
w:endInsAuthor=3D"gould"
w:endInsDate=3D"2004-09-24T03:25:00Z"><font color=3Dnavy><span =
style=3D'color:navy'>716-845-5702</span></font></ns0:PlaceType></ns0:plac=
e></span></font><o:p></o:p></p>
</div>
<div>
<div class=3DMsoNormal align=3Dcenter style=3D'text-align:center'><font =
size=3D3
face=3DPMingLiU><span style=3D'font-size:12.0pt'>
<hr size=3D2 width=3D"100%" align=3Dcenter tabindex=3D-1>
</span></font></div>
<p class=3DMsoNormal><b><font size=3D2 face=3DTahoma><span =
style=3D'font-size:10.0pt;
font-family:Tahoma;font-weight:bold'>From:</span></font></b><font =
size=3D2
face=3DTahoma><span style=3D'font-size:10.0pt;font-family:Tahoma'> =
snort-users-admin@lists.sourceforge.net
[mailto:snort-users-admin@lists.sourceforge.net] <b><span =
style=3D'font-weight:
bold'>On Behalf Of </span></b>kinux<br>
<b><span style=3D'font-weight:bold'>Sent:</span></b> Friday, September =
24, 2004
2:10 AM<br>
<b><span style=3D'font-weight:bold'>To:</span></b>
snort-users@lists.sourceforge.net<br>
<b><span style=3D'font-weight:bold'>Subject:</span></b> [Snort-users] An =
acid
problem.</span></font><o:p></o:p></p>
</div>
<p class=3DMsoNormal><font size=3D3 face=3DPMingLiU><span =
style=3D'font-size:12.0pt'><o:p> </o:p></span></font></p>
<div>
<p class=3DMsoNormal><font size=3D3 face=3DPMingLiU><span =
style=3D'font-size:12.0pt'>hi,<o:p></o:p></span></font></p>
</div>
<div>
<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt;font-family:"Times New =
Roman"'> </span></font><o:p></o:p></p>
</div>
<div>
<p class=3DMsoNormal><font size=3D3 face=3DPMingLiU><span =
style=3D'font-size:12.0pt'>i
installed snort, mysql, acid by ports on a freebsd =
box.</span></font><font
size=3D2><span style=3D'font-size:10.0pt'> </span></font><o:p></o:p></p>
</div>
<div>
<p class=3DMsoNormal><font size=3D3 face=3DPMingLiU><span =
style=3D'font-size:12.0pt'>When
i try to display Alert Listing: 15 Last Alerts, there is nothing show on =
the<br>
screen.</span></font><font face=3D"Times New Roman"><span =
style=3D'font-family:
"Times New Roman"'> </span></font> as following.<font
face=3D"Times New Roman"><span style=3D'font-family:"Times New =
Roman"'> </span></font>
What's the problem?<br>
<br>
<font face=3D"Times New Roman"><span style=3D'font-family:"Times New =
Roman"'> </span></font>
ACID<br>
<font face=3D"Times New Roman"><span style=3D'font-family:"Times New =
Roman"'> </span></font>
Alert Listing: 15 Last Alerts Home<br>
<font face=3D"Times New Roman"><span style=3D'font-family:"Times New =
Roman"'>  =
;</span></font>
Search<font face=3D"Times New Roman"><span style=3D'font-family:"Times =
New Roman"'> </span></font>
|<font face=3D"Times New Roman"><span style=3D'font-family:"Times New =
Roman"'> </span></font>
AG Maintenance<br>
<br>
<font face=3D"Times New Roman"><span style=3D'font-family:"Times New =
Roman"'> </span></font>
[ Back ]<br>
<br>
Added 0 alert(s) to the Alert cache<br>
<font face=3D"Times New Roman"><span style=3D'font-family:"Times New =
Roman"'> </span></font>Queried
DB on : Fri September 24, 2004 10:22:20 Meta Criteria<font
face=3D"Times New Roman"><span style=3D'font-family:"Times New =
Roman"'> </span></font>
any<br>
<font face=3D"Times New Roman"><span style=3D'font-family:"Times New =
Roman"'>  =
; </span></font>
IP Criteria<font face=3D"Times New Roman"><span =
style=3D'font-family:"Times New Roman"'> </span></font>
any<br>
<font face=3D"Times New Roman"><span style=3D'font-family:"Times New =
Roman"'>  =
; </span></font>
Layer 4 Criteria<font face=3D"Times New Roman"><span =
style=3D'font-family:"Times New Roman"'> </span></font>
none<br>
<font face=3D"Times New Roman"><span style=3D'font-family:"Times New =
Roman"'>  =
; </span></font>
Payload Criteria<font face=3D"Times New Roman"><span =
style=3D'font-family:"Times New Roman"'> </span></font>
any<br>
<br>
<br>
<br>
<br>
Displaying 15 Last Alerts<br>
<br>
<font size=3D2><span =
style=3D'font-size:10.0pt'>Thanks.</span></font><o:p></o:p></p>
</div>
<div>
<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt;font-family:"Times New =
Roman"'> </span></font><o:p></o:p></p>
</div>
</div>
</body>
</html>
------_=_NextPart_001_01C4A208.A27D7072--
-------------------------------------------------------
This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170
Project Admins to receive an Apple iPod Mini FREE for your judgement on
who ports your project to Linux PPC the best. Sponsored by IBM.
Deadline: Sept. 24. Go here: http://sf.net/ppc_contest.php
________________________________________
_______
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists...nfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf....ist=snort-users
| |
|
| This is a multi-part message in MIME format.
------=_NextPart_000_00B6_01C4A2A9.AD8E66A0
Content-Type: text/plain;
charset="ISO-8859-1"
Content-Transfer-Encoding: quoted-printable
In snort.conf, i have choose to use mysql..
# database: log to a variety of databases
# ---------------------------------------
# See the README.database file for more information about configuring
# and using this plugin.
#
output database: log, mysql, user=3Dsnort password=3D123454 =
dbname=3Dsnort host=3Dlocalhost
----- Original Message -----=20
From: Gould, Scott=20
To: snort-users@lists.sourceforge.net=20
Sent: Friday, September 24, 2004 3:32 PM
Subject: RE: [Snort-users] An acid problem.
My 1st thought would be to check your snort.conf file for the =
appropriate output plug-in configuration. You need to tell snort to log =
to your mysql db, via an output db plug-in line in your snort.conf =
file..
=20
The documentation at snort.org and the snort.conf file give examples =
of database output logging.
=20
This, is however a method that may not be able to keep up with high =
bandwidth. You may want to consider a flow like this if you have high =
bandwidth pipes your monitoring:
=20
Snort logs to binary log file
Barnyard monitors binary log file, and does inserts into mysql db
=20
Lots of information about barnyard can be found in the various setup =
docs available at snort.org, and by searching the archives of this list.
=20
My best advice, only being at this for a year or so myself, is to =
start simple (which your doingJ), get your current setup working, then =
look to tune performance down the road.
=20
Hope this helps.
=20
Scott Gould, MCP
Senior Network & Systems Analyst
Gynecologic Oncology Group=20
Statistical & Data Center
sgould@gogstats.org
716-845-5702
-------------------------------------------------------------------------=
-----
From: snort-users-admin@lists.sourceforge.net =
[mailto:snort-users-admin@lists.sourceforge.net] On Behalf Of kinux
Sent: Friday, September 24, 2004 2:10 AM
To: snort-users@lists.sourceforge.net
Subject: [Snort-users] An acid problem.
=20
hi,
=20
i installed snort, mysql, acid by ports on a freebsd box.=20
When i try to display Alert Listing: 15 Last Alerts, there is nothing =
show on the
screen. as following. What's the problem?
ACID
Alert Listing: 15 Last Alerts Home
Search | AG Maintenance
[ Back ]
Added 0 alert(s) to the Alert cache
Queried DB on : Fri September 24, 2004 10:22:20 Meta Criteria any
IP Criteria any
Layer 4 Criteria none
Payload Criteria any
Displaying 15 Last Alerts
Thanks.
=20
------=_NextPart_000_00B6_01C4A2A9.AD8E66A0
Content-Type: text/html;
charset="ISO-8859-1"
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML xmlns=3D"http://www.w3.org/TR/REC-html40" xmlns:v =3D=20
"urn:schemas-microsoft-com:vml" xmlns:o =3D=20
"urn:schemas-microsoft-com:office:office" xmlns:w =3D=20
"urn:schemas-microsoft-com:office:word" xmlns:st1 =3D=20
"urn:schemas-microsoft-com:office:smarttags" xmlns:ns0 =3D=20
"urn:schemas-microsoft-com:office:smarttags"><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Diso-8859-1">
<META content=3D"MSHTML 6.00.2800.1458" name=3DGENERATOR><!--[if !mso]>
<STYLE>v\:* {
BEHAVIOR: url(#default#VML)
}
o\:* {
BEHAVIOR: url(#default#VML)
}
w\:* {
BEHAVIOR: url(#default#VML)
}
..shape {
BEHAVIOR: url(#default#VML)
}
</STYLE>
<![endif]--><o:SmartTagType name=3D"PlaceType"=20
namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"></o:SmartTagT=
ype><o:SmartTagType=20
name=3D"PlaceName"=20
namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"></o:SmartTagT=
ype><o:SmartTagType=20
name=3D"place"=20
namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"></o:SmartTagT=
ype><o:SmartTagType=20
name=3D"PersonName"=20
namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"></o:SmartTagT=
ype><!--[if !mso]>
<STYLE>
st1\:*{behavior:url(#default#ieooui) }
</STYLE>
<![endif]-->
<STYLE>
<!--
/* Font Definitions */
@font-face
{font-family:Wingdings;
panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
{font-family:PMingLiU;
panose-1:2 1 6 1 0 1 1 1 1 1;}
@font-face
{font-family:Tahoma;
panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
{font-family:"\@PMingLiU";
panose-1:0 0 0 0 0 0 0 0 0 0;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:PMingLiU;}
a:link, span.MsoHyperlink
{color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{color:purple;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-reply;
font-family:Arial;
color:navy;}
@page Section1
{size:8.5in 11.0in;
margin:1.0in 1.25in 1.0in 1.25in;}
div.Section1
{page:Section1;}
-->
</STYLE>
<!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></HEAD>
<BODY lang=3DEN-US vLink=3Dpurple link=3Dblue bgColor=3Dwhite>
<DIV><FONT face=3D新細明體 size=3D2>In =
snort.conf, i have choose to use=20
mysql..</FONT></DIV>
<DIV><FONT face=3D新細明體 =
size=3D2></FONT> </DIV>
<DIV><FONT face=3D新細明體 size=3D2># database: =
log to a variety of databases<BR>#=20
---------------------------------------<BR># See the README.database =
file for=20
more information about configuring<BR># and using this =
plugin.<BR>#<BR>output=20
database: log, mysql, user=3Dsnort password=3D123454 dbname=3Dsnort=20
host=3Dlocalhost</FONT></DIV>
<DIV><FONT face=3D新細明體 =
size=3D2></FONT> </DIV>
<DIV><FONT face=3D新細明體 size=3D2> </DIV>
<DIV><BR></DIV></FONT>
<BLOCKQUOTE dir=3Dltr=20
style=3D"PADDING-RIGHT: 0px; PADDING-LEFT: 5px; MARGIN-LEFT: 5px; =
BORDER-LEFT: #000000 2px solid; MARGIN-RIGHT: 0px">
<DIV style=3D"FONT: 10pt 新細明體">----- =
Original Message ----- </DIV>
<DIV=20
style=3D"BACKGROUND: #e4e4e4; FONT: 10pt =
新細明體; font-color: black"><B>From:</B>=20
<A title=3Dsgould@gogstats.org =
href=3D"mailto:sgould@gogstats.org">Gould,=20
Scott</A> </DIV>
<DIV style=3D"FONT: 10pt 新細明體"><B>To:</B> =
<A=20
title=3Dsnort-users@lists.sourceforge.net=20
=
href=3D"mailto:snort-users@lists.sourceforge.net">snort-users@lists.sourc=
eforge.net</A>=20
</DIV>
<DIV style=3D"FONT: 10pt =
新細明體"><B>Sent:</B> Friday, September 24, =
2004 3:32=20
PM</DIV>
<DIV style=3D"FONT: 10pt =
新細明體"><B>Subject:</B> RE: [Snort-users] An =
acid=20
problem.</DIV>
<DIV><BR></DIV>
<DIV class=3DSection1>
<P class=3DMsoNormal><FONT face=3DArial color=3Dnavy size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Arial">My =
1<SUP>st</SUP>=20
thought would be to check your snort.conf file for the appropriate =
output=20
plug-in configuration. You need to tell snort to log to your =
mysql db,=20
via an output db plug-in line in your snort.conf=20
file..<o:p></o:p></SPAN></FONT></P>
<P class=3DMsoNormal><FONT face=3DArial color=3Dnavy size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: =
Arial"><o:p> </o:p></SPAN></FONT></P>
<P class=3DMsoNormal><FONT face=3DArial color=3Dnavy size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Arial">The =
documentation at=20
snort.org and the snort.conf file give examples of database output=20
logging.<o:p></o:p></SPAN></FONT></P>
<P class=3DMsoNormal><FONT face=3DArial color=3Dnavy size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: =
Arial"><o:p> </o:p></SPAN></FONT></P>
<P class=3DMsoNormal><FONT face=3DArial color=3Dnavy size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Arial">This, is =
however a=20
method that may not be able to keep up with high bandwidth. You =
may want=20
to consider a flow like this if you have high bandwidth pipes your=20
monitoring:<o:p></o:p></SPAN></FONT></P>
<P class=3DMsoNormal><FONT face=3DArial color=3Dnavy size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: =
Arial"><o:p> </o:p></SPAN></FONT></P>
<P class=3DMsoNormal><FONT face=3DArial color=3Dnavy size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Arial">Snort logs =
to binary=20
log file<o:p></o:p></SPAN></FONT></P>
<P class=3DMsoNormal><FONT face=3DArial color=3Dnavy size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Arial">Barnyard =
monitors=20
binary log file, and does inserts into mysql =
db<o:p></o:p></SPAN></FONT></P>
<P class=3DMsoNormal><FONT face=3DArial color=3Dnavy size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: =
Arial"><o:p> </o:p></SPAN></FONT></P>
<P class=3DMsoNormal><FONT face=3DArial color=3Dnavy size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Arial">Lots of =
information=20
about barnyard can be found in the various setup docs available at =
snort.org,=20
and by searching the archives of this =
list.<o:p></o:p></SPAN></FONT></P>
<P class=3DMsoNormal><FONT face=3DArial color=3Dnavy size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: =
Arial"><o:p> </o:p></SPAN></FONT></P>
<P class=3DMsoNormal><FONT face=3DArial color=3Dnavy size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Arial">My best =
advice, only=20
being at this for a year or so myself, is to start simple (which your=20
doing</SPAN></FONT><FONT face=3DWingdings color=3Dnavy size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: =
Wingdings">J</SPAN></FONT><FONT=20
face=3DArial color=3Dnavy size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Arial"> ), get your =
current=20
setup working, then look to tune performance down the=20
road.<o:p></o:p></SPAN></FONT></P>
<P class=3DMsoNormal><FONT face=3DArial color=3Dnavy size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: =
Arial"><o:p> </o:p></SPAN></FONT></P>
<P class=3DMsoNormal><FONT face=3DArial color=3Dnavy size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Arial">Hope this=20
helps.<o:p></o:p></SPAN></FONT></P>
<P class=3DMsoNormal><FONT face=3DArial color=3Dnavy size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: =
Arial"><o:p> </o:p></SPAN></FONT></P>
<DIV>
<P class=3DMsoNormal><FONT face=3DArial color=3Dnavy size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Arial">Scott =
Gould,=20
MCP</SPAN></FONT><FONT color=3Dnavy><SPAN=20
style=3D"COLOR: navy"><o:p></o:p></SPAN></FONT></P>
<P class=3DMsoNormal><FONT face=3DArial color=3Dnavy size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Arial">Senior =
Network &=20
Systems Analyst</SPAN></FONT><FONT color=3Dnavy><SPAN=20
style=3D"COLOR: navy"><o:p></o:p></SPAN></FONT></P>
<P class=3DMsoNormal><FONT face=3DArial color=3Dnavy size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Arial">Gynecologic =
Oncology=20
Group </SPAN></FONT><FONT color=3Dnavy><SPAN=20
style=3D"COLOR: navy"><o:p></o:p></SPAN></FONT></P>
<P class=3DMsoNormal><FONT face=3DArial color=3Dnavy size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Arial">Statistical =
&=20
</SPAN></FONT><FONT face=3DArial size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; FONT-FAMILY: Arial"><ns0:place=20
w:endInsDate=3D"2004-09-24T03:25:00Z" w:endInsAuthor=3D"gould"=20
w:insDate=3D"2004-09-24T03:25:00Z" =
w:insAuthor=3D"gould"><ns0:PlaceName=20
w:endInsDate=3D"2004-09-24T03:25:00Z" w:endInsAuthor=3D"gould"=20
w:insDate=3D"2004-09-24T03:25:00Z" w:insAuthor=3D"gould"><st1:place=20
w:st=3D"on"><st1:PlaceName w:st=3D"on"><FONT color=3Dnavy><SPAN=20
style=3D"COLOR: =
navy">Data</SPAN></FONT></st1:PlaceName></ns0:PlaceName></st1:place><FONT=
=20
color=3Dnavy><SPAN style=3D"COLOR: navy"> </SPAN></FONT><ns0:PlaceType =
w:endInsDate=3D"2004-09-24T03:25:00Z" w:endInsAuthor=3D"gould"=20
w:insDate=3D"2004-09-24T03:25:00Z" =
w:insAuthor=3D"gould"><st1:PlaceType=20
w:st=3D"on"><FONT color=3Dnavy><SPAN=20
style=3D"COLOR: =
navy">Center</SPAN></FONT></st1:PlaceType></ns0:PlaceType></ns0:place></S=
PAN></FONT><FONT=20
color=3Dnavy><SPAN style=3D"COLOR: navy"><o:p></o:p></SPAN></FONT></P>
<P class=3DMsoNormal><FONT face=3DArial size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; FONT-FAMILY: Arial"><ns0:place=20
w:endInsDate=3D"2004-09-24T03:25:00Z" w:endInsAuthor=3D"gould"=20
w:insDate=3D"2004-09-24T03:25:00Z" =
w:insAuthor=3D"gould"><ns0:PlaceType=20
w:endInsDate=3D"2004-09-24T03:25:00Z" w:endInsAuthor=3D"gould"=20
w:insDate=3D"2004-09-24T03:25:00Z" w:insAuthor=3D"gould"><FONT =
color=3Dnavy><SPAN=20
style=3D"COLOR: =
navy">sgould@gogstats.org</SPAN></FONT></ns0:PlaceType></ns0:place></SPAN=
></FONT><FONT=20
color=3Dnavy><SPAN style=3D"COLOR: navy"><o:p></o:p></SPAN></FONT></P>
<P class=3DMsoNormal><FONT face=3DArial size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt; FONT-FAMILY: Arial"><ns0:place=20
w:endInsDate=3D"2004-09-24T03:25:00Z" w:endInsAuthor=3D"gould"=20
w:insDate=3D"2004-09-24T03:25:00Z" =
w:insAuthor=3D"gould"><ns0:PlaceType=20
w:endInsDate=3D"2004-09-24T03:25:00Z" w:endInsAuthor=3D"gould"=20
w:insDate=3D"2004-09-24T03:25:00Z" w:insAuthor=3D"gould"><FONT =
color=3Dnavy><SPAN=20
style=3D"COLOR: =
navy">716-845-5702</SPAN></FONT></ns0:PlaceType></ns0:place></SPAN></FONT=
><o:p></o:p></P></DIV>
<DIV>
<DIV class=3DMsoNormal style=3D"TEXT-ALIGN: center" =
align=3Dcenter><FONT=20
face=3DPMingLiU size=3D3><SPAN style=3D"FONT-SIZE: 12pt">
<HR tabIndex=3D-1 align=3Dcenter width=3D"100%" SIZE=3D2>
</SPAN></FONT></DIV>
<P class=3DMsoNormal><B><FONT face=3DTahoma size=3D2><SPAN=20
style=3D"FONT-WEIGHT: bold; FONT-SIZE: 10pt; FONT-FAMILY: =
Tahoma">From:</SPAN></FONT></B><FONT=20
face=3DTahoma size=3D2><SPAN style=3D"FONT-SIZE: 10pt; FONT-FAMILY: =
Tahoma">=20
snort-users-admin@lists.sourceforge.net=20
[mailto:snort-users-admin@lists.sourceforge.net] <B><SPAN=20
style=3D"FONT-WEIGHT: bold">On Behalf Of </SPAN></B>kinux<BR><B><SPAN=20
style=3D"FONT-WEIGHT: bold">Sent:</SPAN></B> Friday, September 24, =
2004 2:10=20
AM<BR><B><SPAN style=3D"FONT-WEIGHT: bold">To:</SPAN></B>=20
snort-users@lists.sourceforge.net<BR><B><SPAN=20
style=3D"FONT-WEIGHT: bold">Subject:</SPAN></B> [Snort-users] An acid=20
problem.</SPAN></FONT><o:p></o:p></P></DIV>
<P class=3DMsoNormal><FONT face=3DPMingLiU size=3D3><SPAN=20
style=3D"FONT-SIZE: 12pt"><o:p> </o:p></SPAN></FONT></P>
<DIV>
<P class=3DMsoNormal><FONT face=3DPMingLiU size=3D3><SPAN=20
style=3D"FONT-SIZE: 12pt">hi,<o:p></o:p></SPAN></FONT></P></DIV>
<DIV>
<P class=3DMsoNormal><FONT face=3D"Times New Roman" size=3D3><SPAN=20
style=3D"FONT-SIZE: 12pt; FONT-FAMILY: 'Times New =
Roman'"> </SPAN></FONT><o:p></o:p></P></DIV>
<DIV>
<P class=3DMsoNormal><FONT face=3DPMingLiU size=3D3><SPAN =
style=3D"FONT-SIZE: 12pt">i=20
installed snort, mysql, acid by ports on a freebsd =
box.</SPAN></FONT><FONT=20
size=3D2><SPAN style=3D"FONT-SIZE: 10pt"> =
</SPAN></FONT><o:p></o:p></P></DIV>
<DIV>
<P class=3DMsoNormal><FONT face=3DPMingLiU size=3D3><SPAN=20
style=3D"FONT-SIZE: 12pt">When i try to display Alert Listing: 15 Last =
Alerts,=20
there is nothing show on the<BR>screen.</SPAN></FONT><FONT=20
face=3D"Times New Roman"><SPAN=20
style=3D"FONT-FAMILY: 'Times New Roman'"> </SPAN></FONT> as =
following.<FONT=20
face=3D"Times New Roman"><SPAN=20
style=3D"FONT-FAMILY: 'Times New Roman'"> </SPAN></FONT> What's =
the=20
problem?<BR><BR><FONT face=3D"Times New Roman"><SPAN=20
style=3D"FONT-FAMILY: 'Times New =
Roman'"> </SPAN></FONT>=20
ACID<BR><FONT face=3D"Times New Roman"><SPAN=20
style=3D"FONT-FAMILY: 'Times New =
Roman'"> </SPAN></FONT>=20
Alert Listing: 15 Last Alerts Home<BR><FONT face=3D"Times New =
Roman"><SPAN=20
style=3D"FONT-FAMILY: 'Times New =
Roman'">  =
;</SPAN></FONT>=20
Search<FONT face=3D"Times New Roman"><SPAN=20
style=3D"FONT-FAMILY: 'Times New Roman'"> </SPAN></FONT> =
|<FONT=20
face=3D"Times New Roman"><SPAN=20
style=3D"FONT-FAMILY: 'Times New Roman'"> </SPAN></FONT> AG =
Maintenance<BR><BR><FONT face=3D"Times New Roman"><SPAN=20
style=3D"FONT-FAMILY: 'Times New =
Roman'"> </SPAN></FONT>=20
[ Back ]<BR><BR>Added 0 alert(s) to the Alert cache<BR><FONT=20
face=3D"Times New Roman"><SPAN=20
style=3D"FONT-FAMILY: 'Times New Roman'"> </SPAN></FONT>Queried =
DB on : Fri=20
September 24, 2004 10:22:20 Meta Criteria<FONT face=3D"Times New =
Roman"><SPAN=20
style=3D"FONT-FAMILY: 'Times New =
Roman'"> </SPAN></FONT>=20
any<BR><FONT face=3D"Times New Roman"><SPAN=20
style=3D"FONT-FAMILY: 'Times New =
Roman'">  =
; </SPAN></FONT>=20
IP Criteria<FONT face=3D"Times New Roman"><SPAN=20
style=3D"FONT-FAMILY: 'Times New =
Roman'"> </SPAN></FONT>=20
any<BR><FONT face=3D"Times New Roman"><SPAN=20
style=3D"FONT-FAMILY: 'Times New =
Roman'">  =
; </SPAN></FONT>=20
Layer 4 Criteria<FONT face=3D"Times New Roman"><SPAN=20
style=3D"FONT-FAMILY: 'Times New =
Roman'"> </SPAN></FONT>=20
none<BR><FONT face=3D"Times New Roman"><SPAN=20
style=3D"FONT-FAMILY: 'Times New =
Roman'">  =
; </SPAN></FONT>=20
Payload Criteria<FONT face=3D"Times New Roman"><SPAN=20
style=3D"FONT-FAMILY: 'Times New =
Roman'"> </SPAN></FONT>=20
any<BR><BR><BR><BR><BR>Displaying 15 Last Alerts<BR><BR><FONT =
size=3D2><SPAN=20
style=3D"FONT-SIZE: 10pt">Thanks.</SPAN></FONT><o:p></o:p></P></DIV>
<DIV>
<P class=3DMsoNormal><FONT face=3D"Times New Roman" size=3D3><SPAN=20
style=3D"FONT-SIZE: 12pt; FONT-FAMILY: 'Times New =
Roman'"> </SPAN></FONT><o:p></o:p></P></DIV></DIV></BLOCKQUOTE></BOD=
Y></HTML>
------=_NextPart_000_00B6_01C4A2A9.AD8E66A0--
-------------------------------------------------------
This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170
Project Admins to receive an Apple iPod Mini FREE for your judgement on
who ports your project to Linux PPC the best. Sponsored by IBM.
Deadline: Sept. 24. Go here: http://sf.net/ppc_contest.php
________________________________________
_______
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists...nfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf....ist=snort-users
|
|
|
|
|