This is Interesting: Free IT Magazines  
Home > Archive > Snort > September 2004 > [Snort-users] Upgrade of Snort





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author [Snort-users] Upgrade of Snort
O'Flynn, Derek

2004-09-24, 5:46 pm

This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

------_=_NextPart_001_01C4A27D.EAB58896
Content-Type: text/plain

I just did an upgrade for 2.0 to 2.2. I rebuilt it and overlayed the old
binary. I also utilized the new snort.conf and ported my specific
configurations over to it. I dropped the tables in mysql and rebuilt them
using the create_mysql and snortdb-extra configs. Updated the .config and
..map files to my etc directory.



Anyway, it looks like it comes up fine, and then crashes out with a file
size error. Anyone know how to correct it?



rpc_decode arguments:

Ports to decode RPC on: 111 32771

alert_fragments: INACTIVE

alert_large_fragments: ACTIVE

alert_incomplete: ACTIVE

alert_multiple_requests: ACTIVE

telnet_decode arguments:

Ports to decode telnet on: 21 23 25 119

database: compiled support for ( mysql )

database: configured to use mysql

database: user = snort

database: password is set

database: database name = snort

database: host = localhost

database: sensor name = 192.168.100.100

database: sensor id = 1

database: schema version = 106

database: using the "log" facility

1889 Snort rules read...

1889 Option Chains linked into 196 Chain Headers

0 Dynamic rules

++++++++++++++++++++++++++++++++++++++++
+++++++++++



Warning: flowbits key 'realplayer.playlist' is checked but not ever set.



+-----------------------[thresholding-config]-------------------------------
---

| memory-cap : 1048576 bytes

+-----------------------[thresholding-global]-------------------------------
---

| none

+-----------------------[thresholding-local]--------------------------------
---

| gen-id=1 sig-id=2495 type=Both tracking=dst count=20
seconds=60

| gen-id=1 sig-id=2523 type=Both tracking=dst count=10
seconds=10

| gen-id=1 sig-id=2494 type=Both tracking=dst count=20
seconds=60

| gen-id=1 sig-id=2275 type=Threshold tracking=dst count=5
seconds=60

| gen-id=1 sig-id=2496 type=Both tracking=dst count=20
seconds=60

+-----------------------[suppression]---------------------------------------
---

----------------------------------------------------------------------------
---

Rule application order: ->activation->dynamic->alert->pass->log



--== Initialization Complete ==--



-*> Snort! <*-

Version 2.2.0 (Build 30)

By Martin Roesch (roesch@sourcefire.com, www.snort.org)

File size limit exceeded



Thanks,

Derek O'Flynn


------_=_NextPart_001_01C4A27D.EAB58896
Content-Type: text/html
Content-Transfer-Encoding: quoted-printable

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Dus-ascii">


<meta name=3DGenerator content=3D"Microsoft Word 11 (filtered medium)">
<style>
<!--
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman";}
a:link, span.MsoHyperlink
{color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{color:purple;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:Arial;
color:windowtext;}
@page Section1
{size:8.5in 11.0in;
margin:1.0in 1.25in 1.0in 1.25in;}
div.Section1
{page:Section1;}
-->
</style>

</head>

<body lang=3DEN-US link=3Dblue vlink=3Dpurple>

<div class=3DSection1>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>I just did an upgrade for 2.0 to 2.2.&nbsp; I =
rebuilt it and
overlayed the old binary.&nbsp; I also utilized the new snort.conf and =
ported my
specific configurations over to it.&nbsp; I dropped the tables in mysql =
and rebuilt
them using the create_mysql and snortdb-extra configs.&nbsp; Updated =
the .config and
..map files to my etc directory.<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>Anyway, it looks like it comes up fine, and then =
crashes out
with a file size error.&nbsp; Anyone know how to correct =
it?<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>rpc_decode arguments:<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>&nbsp;&nbsp;&nbsp; Ports to decode RPC on: 111 32771 =
<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>&nbsp;&nbsp;&nbsp; alert_fragments: =
INACTIVE<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>&nbsp;&nbsp;&nbsp; alert_large_fragments: =
ACTIVE<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>&nbsp;&nbsp;&nbsp; alert_incomplete: =
ACTIVE<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>&nbsp;&nbsp;&nbsp; alert_multiple_requests: =
ACTIVE<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>telnet_decode =
arguments:<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>&nbsp;&nbsp;&nbsp; Ports to decode telnet on: 21 23 =
25 119 <o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>database: compiled support for ( mysql =
)<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>database: configured to use =
mysql<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>database:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp; user =3D snort<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>database: password is =
set<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>database: database name =3D =
snort<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>database:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp; host =3D localhost<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>database: &nbsp;&nbsp;sensor name =3D =
192.168.100.100<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>database:&nbsp;&nbsp;&nbsp;&nbsp; sensor id =3D =
1<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>database: schema version =3D =
106<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>database: using the "log" =
facility<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>1889 Snort rules =
read...<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>1889 Option Chains linked into 196 Chain =
Headers<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>0 Dynamic rules<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'> ++++++++++++++++++++++++++++++++++++++++
+++++++++++<o=
:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>Warning: flowbits key 'realplayer.playlist' is =
checked but
not ever set.<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>+-----------------------[thresholding-config]--------=
--------------------------<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>| memory-cap : 1048576 =
bytes<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>+-----------------------[thresholding-global]--------=
--------------------------<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>| none<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>+-----------------------[thresholding-local]---------=
--------------------------<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>| gen-id=3D1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
sig-id=3D2495&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
type=3DBoth&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
tracking=3Ddst count=3D20&nbsp; seconds=3D60 =
<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>| gen-id=3D1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
sig-id=3D2523&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
type=3DBoth&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
tracking=3Ddst count=3D10&nbsp; seconds=3D10 =
<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>| gen-id=3D1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
sig-id=3D2494&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
type=3DBoth&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
tracking=3Ddst count=3D20&nbsp; seconds=3D60 =
<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>| gen-id=3D1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sig-id=3D2=
275&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; type=3DThreshold
tracking=3Ddst count=3D5&nbsp;&nbsp; seconds=3D60 =
<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>| gen-id=3D1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
sig-id=3D2496&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
type=3DBoth&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
tracking=3Ddst count=3D20&nbsp; seconds=3D60 =
<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>+-----------------------[suppression]----------------=
--------------------------<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>-----------------------------------------------------=
--------------------------<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>Rule application order:
-&gt;activation-&gt;dynamic-&gt;alert-&gt;pass-&gt;log<o:p></o:p></span>=
</font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; --=3D=3D =
Initialization Complete =3D=3D--<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>-*&gt; Snort! &lt;*-<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>Version 2.2.0 (Build =
30)<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>By Martin Roesch (roesch@sourcefire.com, =
www.snort.org)<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>File size limit =
exceeded<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>Thanks,<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>Derek O'Flynn</span></font><o:p></o:p></p>

</div>

</body>

</html>

------_=_NextPart_001_01C4A27D.EAB58896--


-------------------------------------------------------
This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170
Project Admins to receive an Apple iPod Mini FREE for your judgement on
who ports your project to Linux PPC the best. Sponsored by IBM.
Deadline: Sept. 24. Go here: http://sf.net/ppc_contest.php
________________________________________
_______
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists...nfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf....ist=snort-users
O'Flynn, Derek

2004-09-24, 5:46 pm

This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

------_=_NextPart_001_01C4A281.53BB1C0E
Content-Type: text/plain

An update,



I found the problem, on a hunch I checked /var/log/snort and noticed a big
ol' file sitting there. So I deleted it...problem fixed. Why is snort
logging to this file when I have it configured to replicate the events to a
db?



Derek O'Flynn

Enterprise Information Security

LSU Health Sciences Center

doflyn@lsuhsc.edu <mailto:doflyn@lsuhsc.edu> (504)568-6130

_____

From: snort-users-admin@lists.sourceforge.net
[mailto:snort-users-admin@lists.sourceforge.net] On Behalf Of O'Flynn, Derek
Sent: Friday, September 24, 2004 4:33 PM
To: 'snort-users@lists.sourceforge.net'
Subject: [Snort-users] Upgrade of Snort



I just did an upgrade for 2.0 to 2.2. I rebuilt it and overlayed the old
binary. I also utilized the new snort.conf and ported my specific
configurations over to it. I dropped the tables in mysql and rebuilt them
using the create_mysql and snortdb-extra configs. Updated the .config and
..map files to my etc directory.



Anyway, it looks like it comes up fine, and then crashes out with a file
size error. Anyone know how to correct it?



rpc_decode arguments:

Ports to decode RPC on: 111 32771

alert_fragments: INACTIVE

alert_large_fragments: ACTIVE

alert_incomplete: ACTIVE

alert_multiple_requests: ACTIVE

telnet_decode arguments:

Ports to decode telnet on: 21 23 25 119

database: compiled support for ( mysql )

database: configured to use mysql

database: user = snort

database: password is set

database: database name = snort

database: host = localhost

database: sensor name = 192.168.100.100

database: sensor id = 1

database: schema version = 106

database: using the "log" facility

1889 Snort rules read...

1889 Option Chains linked into 196 Chain Headers

0 Dynamic rules

++++++++++++++++++++++++++++++++++++++++
+++++++++++



Warning: flowbits key 'realplayer.playlist' is checked but not ever set.



+-----------------------[thresholding-config]-------------------------------
---

| memory-cap : 1048576 bytes

+-----------------------[thresholding-global]-------------------------------
---

| none

+-----------------------[thresholding-local]--------------------------------
---

| gen-id=1 sig-id=2495 type=Both tracking=dst count=20
seconds=60

| gen-id=1 sig-id=2523 type=Both tracking=dst count=10
seconds=10

| gen-id=1 sig-id=2494 type=Both tracking=dst count=20
seconds=60

| gen-id=1 sig-id=2275 type=Threshold tracking=dst count=5
seconds=60

| gen-id=1 sig-id=2496 type=Both tracking=dst count=20
seconds=60

+-----------------------[suppression]---------------------------------------
---

----------------------------------------------------------------------------
---

Rule application order: ->activation->dynamic->alert->pass->log



--== Initialization Complete ==--



-*> Snort! <*-

Version 2.2.0 (Build 30)

By Martin Roesch (roesch@sourcefire.com, www.snort.org)

File size limit exceeded



Thanks,

Derek O'Flynn


------_=_NextPart_001_01C4A281.53BB1C0E
Content-Type: text/html
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:st1=3D"urn:schemas-microsoft-com:office:smarttags" =
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Dus-ascii">


<meta name=3DGenerator content=3D"Microsoft Word 11 (filtered medium)">
<!--[if !mso]>
<style>
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
..shape {behavior:url(#default#VML);}
</style>
<![endif]--><o:SmartTagType
namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags" =
name=3D"PlaceType"/>
<o:SmartTagType =
namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
name=3D"PlaceName"/>
<o:SmartTagType =
namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
name=3D"City"/>
<o:SmartTagType =
namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
name=3D"place" downloadurl=3D"http://www.5iantlavalamp.com/"/>
<!--[if !mso]>
<style>
st1\:*{behavior:url(#default#ieooui) }
</style>
<![endif]-->
<style>
<!--
/* Font Definitions */
@font-face
{font-family:Tahoma;
panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman";}
a:link, span.MsoHyperlink
{color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{color:purple;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal;
font-family:Arial;
color:windowtext;}
span.EmailStyle18
{mso-style-type:personal-reply;
font-family:Arial;
color:navy;}
@page Section1
{size:8.5in 11.0in;
margin:1.0in 1.25in 1.0in 1.25in;}
div.Section1
{page:Section1;}
-->
</style>

</head>

<body lang=3DEN-US link=3Dblue vlink=3Dpurple>

<div class=3DSection1>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>An =
update,<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'><o:p>&nbsp;</o:p></span></font></p>=


<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>I found the problem, on a hunch I =
checked
/var/log/snort and noticed a big ol' file sitting there.&nbsp; So I =
deleted it...problem
fixed.&nbsp; Why is snort logging to this file when I have it =
configured to
replicate the events to a db?<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'><o:p>&nbsp;</o:p></span></font></p>=


<div>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>Derek O'Flynn</span></font><font
color=3Dnavy><span style=3D'color:navy'><o:p></o:p></span></font></p>

<p class=3DMsoNormal><st1:City w:st=3D"on"><st1:place w:st=3D"on"><font =
size=3D2
color=3Dnavy face=3DArial><span =
style=3D'font-size:10.0pt;font-family:Arial;
color:navy'>Enterprise</span></font></st1:place></st1:City><font =
size=3D2
color=3Dnavy face=3DArial><span =
style=3D'font-size:10.0pt;font-family:Arial;
color:navy'> Information Security</span></font><font color=3Dnavy><span
style=3D'color:navy'><o:p></o:p></span></font></p>

<p class=3DMsoNormal><st1:place w:st=3D"on"><st1:PlaceName =
w:st=3D"on"><font size=3D2
color=3Dnavy face=3DArial><span =
style=3D'font-size:10.0pt;font-family:Arial;
color:navy'>LSU</span></font></st1:PlaceName><font size=3D2 =
color=3Dnavy
face=3DArial><span =
style=3D'font-size:10.0pt;font-family:Arial;color:navy'> <st1:PlaceName
w:st=3D"on">Health</st1:PlaceName> <st1:PlaceName =
w:st=3D"on">Sciences</st1:PlaceName>
<st1:PlaceType w:st=3D"on">Center</st1:PlaceType></span></font></st1:pl=
ace><font
color=3Dnavy><span style=3D'color:navy'><o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'><a =
href=3D"mailto:doflyn@lsuhsc.edu">doflyn@lsuhsc.edu</a>
(504)568-6130</span></font><o:p></o:p></p>

</div>

<div>

<div class=3DMsoNormal align=3Dcenter style=3D'text-align:center'><font =
size=3D3
face=3D"Times New Roman"><span style=3D'font-size:12.0pt'>

<hr size=3D2 width=3D"100%" align=3Dcenter tabindex=3D-1>

</span></font></div>

<p class=3DMsoNormal><b><font size=3D2 face=3DTahoma><span =
style=3D'font-size:10.0pt;
font-family:Tahoma;font-weight:bold'>From:</span></font></b><font =
size=3D2
face=3DTahoma><span style=3D'font-size:10.0pt;font-family:Tahoma'>
snort-users-admin@lists.sourceforge.net
[mailto:snort-users-admin@lists.sourceforge.net] <b><span =
style=3D'font-weight:
bold'>On Behalf Of </span></b>O'Flynn, Derek<br>
<b><span style=3D'font-weight:bold'>Sent:</span></b> Friday, September =
24, 2004
4:33 PM<br>
<b><span style=3D'font-weight:bold'>To:</span></b> =
'snort-users@lists.sourceforge.net'<br>
<b><span style=3D'font-weight:bold'>Subject:</span></b> [Snort-users] =
Upgrade of
Snort</span></font><o:p></o:p></p>

</div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>I just did an upgrade for 2.0 to 2.2.&nbsp; I =
rebuilt it and
overlayed the old binary.&nbsp; I also utilized the new snort.conf and =
ported
my specific configurations over to it.&nbsp; I dropped the tables in =
mysql and
rebuilt them using the create_mysql and snortdb-extra configs.&nbsp; =
Updated
the .config and .map files to my etc =
directory.<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>Anyway, it looks like it comes up fine, and then =
crashes out
with a file size error.&nbsp; Anyone know how to correct =
it?<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>rpc_decode arguments:<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>&nbsp;&nbsp;&nbsp; Ports to decode RPC on: 111 32771 =
<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>&nbsp;&nbsp;&nbsp; alert_fragments: =
INACTIVE<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>&nbsp;&nbsp;&nbsp; alert_large_fragments: =
ACTIVE<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>&nbsp;&nbsp;&nbsp; alert_incomplete: =
ACTIVE<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>&nbsp;&nbsp;&nbsp; alert_multiple_requests: =
ACTIVE<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>telnet_decode =
arguments:<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>&nbsp;&nbsp;&nbsp; Ports to decode telnet on: 21 23 =
25 119 <o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>database: compiled support for ( mysql =
)<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>database: configured to use =
mysql<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>database:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;
user =3D snort<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>database: password is =
set<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>database: database name =3D =
snort<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>database:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;
host =3D localhost<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>database: &nbsp;&nbsp;sensor name =3D =
192.168.100.100<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>database:&nbsp;&nbsp;&nbsp;&nbsp; sensor id =3D =
1<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>database: schema version =3D =
106<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>database: using the "log" =
facility<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>1889 Snort rules =
read...<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>1889 Option Chains linked into 196 Chain =
Headers<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>0 Dynamic rules<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'> ++++++++++++++++++++++++++++++++++++++++
+++++++++++<o=
:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>Warning: flowbits key 'realplayer.playlist' is =
checked but
not ever set.<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>+-----------------------[thresholding-config]--------=
--------------------------<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>| memory-cap : 1048576 =
bytes<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>+-----------------------[thresholding-global]--------=
--------------------------<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>| none<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>+-----------------------[thresholding-local]---------=
--------------------------<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>| gen-id=3D1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
sig-id=3D2495&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
type=3DBoth&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; tracking=3Ddst =
count=3D20&nbsp;
seconds=3D60 <o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>| gen-id=3D1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
sig-id=3D2523&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
type=3DBoth&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; tracking=3Ddst =
count=3D10&nbsp;
seconds=3D10 <o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>| gen-id=3D1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
sig-id=3D2494&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
type=3DBoth&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; tracking=3Ddst =
count=3D20&nbsp; seconds=3D60
<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>| gen-id=3D1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
sig-id=3D2275&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; type=3DThreshold =
tracking=3Ddst
count=3D5&nbsp;&nbsp; seconds=3D60 <o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>| gen-id=3D1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
sig-id=3D2496&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
type=3DBoth&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; tracking=3Ddst =
count=3D20&nbsp;
seconds=3D60 <o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>+-----------------------[suppression]----------------=
--------------------------<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>-----------------------------------------------------=
--------------------------<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>Rule application order:
-&gt;activation-&gt;dynamic-&gt;alert-&gt;pass-&gt;log<o:p></o:p></span>=
</font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; --=3D=3D
Initialization Complete =3D=3D--<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>-*&gt; Snort! &lt;*-<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>Version 2.2.0 (Build =
30)<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>By Martin Roesch (roesch@sourcefire.com, =
www.snort.org)<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>File size limit =
exceeded<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>Thanks,<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>Derek O'Flynn</span></font><o:p></o:p></p>

</div>

</body>

</html>

------_=_NextPart_001_01C4A281.53BB1C0E--


-------------------------------------------------------
This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170
Project Admins to receive an Apple iPod Mini FREE for your judgement on
who ports your project to Linux PPC the best. Sponsored by IBM.
Deadline: Sept. 24. Go here: http://sf.net/ppc_contest.php
________________________________________
_______
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists...nfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf....ist=snort-users
Bamm Visscher

2004-09-24, 5:46 pm

Snort has two output facilities: "alert" and "log". Each facility is
assigned a default output format if none is specified. For the alert
facility the default is the /var/log/snort/alert file, for the log
facility, it is those funky addr:port files in /var/log/snort. By
using "output database: log" you have changed the log facility from
the default, to using the DB, but you have done nothing with the alert
facility. Since alert calls log (as long as the function was called
with a pointer to a packet), you can safely turn off any alert output
by using '-A none' (and -N would turn off any log output).

Bammkkkk



----- Original Message -----
From: O'Flynn, Derek <doflyn@lsuhsc.edu>
Date: Fri, 24 Sep 2004 16:57:35 -0500
Subject: RE: [Snort-users] Upgrade of Snort
To: "snort-users@lists.sourceforge.net" <snort-users@lists.sourceforge.net>




An update,



I found the problem, on a hunch I checked /var/log/snort and noticed a
big ol' file sitting there. So I deleted it...problem fixed. Why is
snort logging to this file when I have it configured to replicate the
events to a db?




Derek O'Flynn

Enterprise Information Security

LSU Health Sciences Center

doflyn@lsuhsc.edu (504)568-6130

________________________________


--
sguil - The Analyst Console for NSM
http://sguil.sf.net


-------------------------------------------------------
This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170
Project Admins to receive an Apple iPod Mini FREE for your judgement on
who ports your project to Linux PPC the best. Sponsored by IBM.
Deadline: Sept. 24. Go here: http://sf.net/ppc_contest.php
________________________________________
_______
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists...nfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf....ist=snort-users
Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2010 webservertalk.com