Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: [Snort-users] Fwd: Snort not righting to DB

From: Louis Bohm <lbohm(at)adnexustx.com>
Date: Wed Jun 20 2007 - 10:46:13 EDT


Sorry about that...  

Anyway I am trying Barnyard and having no luck with it. I downloaded ver 0.2 of it from snort.org and compiled it with mysql support. In the barnyard.conf file I am guessing I use the output type for acid if I want to log it into the db???? So I created an output like this:

 output log_aciddb: mysql, sensor_id 1, database snortDB, server localhost, user snortuser, password XXXXX, detail full  

And when I run it barnyard say:

            WARNING /etc/snort/barnyard.conf(138) => Unknown output plugin "log_aciddb" referenced, ignoring!Fatal Error, Quitting..

Exiting  

So how do I tell barnyard about the plugins???  

Louis  

Do you need help?X

~~



Louis Bohm
Network Administrator
Adnexus Therapeutics
781.209.2324

From: snort-users-bounces@lists.sourceforge.net [mailto:snort-users-bounces@lists.sourceforge.net] On Behalf Of Joel Esler
Sent: Wednesday, June 20, 2007 10:15 AM
To: snort-users@lists.sourceforge.net
Subject: [Snort-users] Fwd: Snort not righting to DB        

joel esler | security consultant | Sourcefire | pgp key is public    

Begin forwarded message:

From: "Louis Bohm" <lbohm@adnexustx.com>

Date: June 20, 2007 9:01:16 AM EDT

To: "Joel Esler" <joel.esler@sourcefire.com>

Subject: RE: [Snort-users] Snort not righting to DB

Do you need more help?X

X-Mimeole: Produced By Microsoft Exchange V6.0.6603.0  

Here is my startup command line.

/usr/sbin/snort -A fast -b -d -D -I -i eth1 -u snort -g snort -c /etc/snort/snort.conf -l /var/log/snort/eth1

If I did what you suggest (using a unified output module) what would you recommend I use to do this? What are the differences between the output modules? I ask because I have never used them before.  

Louis    

~~



Louis Bohm
Network Administrator
Adnexus Therapeutics
781.209.2324

From: Joel Esler [mailto:joel.esler@sourcefire.com] Sent: Wednesday, June 20, 2007 8:35 AM
To: Louis Bohm
Cc: snort-users@lists.sourceforge.net
Subject: Re: [Snort-users] Snort not righting to DB  

What is your Snort command line options when you run it?  

Can we help you?X

FWIW -- It is HIGHLY suggested that you not log directly from Snort to the DB. It IS suggested that you use the unified output module and use something like Barnyard or similar to read the unified files and put them in the DB.  

But for now, what does your command line look like?    

On Jun 20, 2007, at 8:08 AM, Louis Bohm wrote:

I am running Snort 2.6.1.5-1 on a Centos 5 machine with MySql 5.0.22-2.1. When I built snort I built it with the mysql option. In the snort.conf file I have the following:

 output database: log, mysql, user=snortuser password=xxxxx dbname=snortDB host=localhost detail=full  

And I am also getting an alert log and a regular log file for each interface.  

At present I am not seeing a lot of events because I have not plugged the box in to a lot of places but I am seeing some and it is showing in the logs. However, I am getting nothing in the database. I am not even seeing a connection between snort and the DB. Snort is reporting NO errors what so ever. And if I run snort -T -c /etc/snort/snort.conf I see that it logs in to the DB with no problems.  

I know this should work I have done it before... Any thoughts?  

Can't find what you're looking for?X

Thanks,

Louis  

~~



Louis Bohm
Network Administrator
Adnexus Therapeutics
781.209.2324
 

-

This SF.net email is sponsored by DB2 Express

Download DB2 Express C - the FREE version of DB2 express and take

control of your XML. No limits. Just data. Click to get it now.

http://sourceforge.net/powerbar/db2/____________________________________

<
http://sourceforge.net/powerbar/db2/___________________________________
____________>

Snort-users mailing list

Snort-users@lists.sourceforge.net
<mailto:Snort-users@lists.sourceforge.net>

Don't know where to look next?X

Go to this URL to change user options or unsubscribe:

https://lists.sourceforge.net/lists/listinfo/snort-users <https://lists.sourceforge.net/lists/listinfo/snort-users>

Snort-users list archive:

http://www.geocrawler.com/redir-sf.php3?list=snort-users <http://www.geocrawler.com/redir-sf.php3?list=snort-users>  



This SF.net email is sponsored by DB2 Express Download DB2 Express C - the FREE version of DB2 express and take control of your XML. No limits. Just data. Click to get it now. http://sourceforge.net/powerbar/db2/



Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users Received on Wed Jun 20 10:47:09 2007

This archive was generated by hypermail 2.1.8 : Wed Jun 20 2007 - 10:50:01 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library