|
|||||||||||
|
RE: [Snort-sigs] Snort Logs
From: Martin Jr., D. Michael <martinm(at)montevallo.edu>
Date: Mon Oct 13 2003 - 12:02:58 EDT
Help??? Michael
-----Original Message-----
Try using Snort with the -X option: -X Dump the raw packet data starting at the link layer. This switch overrides the -l log-dir
Set the output logging directory to log-dir. All
plain
alerts and packet logs go into this directory. If this option
is not specified, the default logging directory is
set
/var/log/snort.
-----Original Message-----
As I have stated before, I am very new to snort and I am using it in a Windows environment (maybe that is my problem) :-0 But I am having a devil of a time with these logs. ANY HELP would be appreciated. I am not using MySQL (yet) for the keeping of the logs but I am having trouble reading the Snort logs that are created. Here is the type of logs I have: --scan.log (text format. Very criptic and not really clear on what was
AND, the following (tcpdump format, maybe? How do read it? Ethereal doesn't know what do with the file.): --snort.alert.(some numeric string)
AND one file that apparently is in tcpdump format that Ethereal can
read:
I don't have many rules even turned on at this point and because I can't read the logs I don't know what else needs to be "tweaked" in Snort. Any assistance would be GREATLY appreciated. Thanks, Michael Martin This SF.net email is sponsored by: SF.net Giveback Program. SourceForge.net hosts over 70,000 Open Source Projects. See the people who have HELPED US provide better services: Click here: http://sourceforge.net/supporters.php Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs This SF.net email is sponsored by: SF.net Giveback Program. SourceForge.net hosts over 70,000 Open Source Projects. See the people who have HELPED US provide better services: Click here: http://sourceforge.net/supporters.php Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs Received on Mon Oct 13 12:49:43 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:08:36 EDT |
||||||||||
|
|||||||||||