Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Snort-Users
[Top] [All Lists]

Re: [Snort-users] Fwd: Snort not righting to DB

Subject: Re: [Snort-users] Fwd: Snort not righting to DB
Date: Wed, 20 Jun 2007 10:46:13 -0400
Sorry about that...

 

Anyway I am trying Barnyard and having no luck with it.  I downloaded
ver 0.2 of it from snort.org and compiled it with mysql support.  In the
barnyard.conf file I am guessing I use the output type for acid if I
want to log it into the db????  So I created an output like this:

 output log_aciddb: mysql, sensor_id 1, database snortDB, server
localhost, user snortuser, password XXXXX, detail full

 

And when I run it barnyard say:

            WARNING /etc/snort/barnyard.conf(138) => Unknown output
plugin "log_aciddb" referenced, ignoring!Fatal Error, Quitting..

Exiting

 

So how do I tell barnyard about the plugins???

 

Louis

 

~~
-------------------------------------
Louis Bohm
Network Administrator
Adnexus Therapeutics
781.209.2324
-------------------------------------

  _____  

From: snort-users-bounces@lists.sourceforge.net
[mailto:snort-users-bounces@lists.sourceforge.net] On Behalf Of Joel
Esler
Sent: Wednesday, June 20, 2007 10:15 AM
To: snort-users@lists.sourceforge.net
Subject: [Snort-users] Fwd: Snort not righting to DB

 

 





 

 

joel esler | security consultant | Sourcefire | pgp  key is public

 





 

Begin forwarded message:





From: "Louis Bohm" <lbohm@adnexustx.com>

Date: June 20, 2007 9:01:16 AM EDT

To: "Joel Esler" <joel.esler@sourcefire.com>

Subject: RE: [Snort-users] Snort not righting to DB

X-Mimeole: Produced By Microsoft Exchange V6.0.6603.0

 

Here is my startup command line. 

/usr/sbin/snort -A fast -b -d -D -I -i eth1 -u snort -g snort -c
/etc/snort/snort.conf -l /var/log/snort/eth1

If I did what you suggest (using a unified output module) what would you
recommend I use to do this?  What are the differences between the output
modules?  I ask because I have never used them before.

 

Louis

 

 

~~
-------------------------------------
Louis Bohm
Network Administrator
Adnexus Therapeutics
781.209.2324
-------------------------------------

  _____  

From: Joel Esler [mailto:joel.esler@sourcefire.com] 
Sent: Wednesday, June 20, 2007 8:35 AM
To: Louis Bohm
Cc: snort-users@lists.sourceforge.net
Subject: Re: [Snort-users] Snort not righting to DB

 

What is your Snort command line options when you run it?

 

FWIW -- It is HIGHLY suggested that you not log directly from Snort to
the DB.  It IS suggested that you use the unified output module and use
something like Barnyard or similar to read the unified files and put
them in the DB.  

 

But for now, what does your command line look like?

 






 

On Jun 20, 2007, at 8:08 AM, Louis Bohm wrote:






I am running Snort 2.6.1.5-1 on a Centos 5 machine with MySql
5.0.22-2.1.  When I built snort I built it with the mysql option.  In
the snort.conf file I have the following:

 output database: log, mysql, user=snortuser password=xxxxx
dbname=snortDB host=localhost detail=full

 

And I am also getting an alert log and a regular log file for each
interface.

 

At present I am not seeing a lot of events because I have not plugged
the box in to a lot of places but I am seeing some and it is showing in
the logs.  However, I am getting nothing in the database.  I am not even
seeing a connection between snort and the DB.  Snort is reporting NO
errors what so ever.  And if I run snort -T -c /etc/snort/snort.conf I
see that it logs in to the DB with no problems.

 

I know this should work I have done it before...  Any thoughts?

 

Thanks,

Louis

 

~~
-------------------------------------
Louis Bohm
Network Administrator
Adnexus Therapeutics
781.209.2324
-------------------------------------

 

------------------------------------------------------------------------
-

This SF.net email is sponsored by DB2 Express

Download DB2 Express C - the FREE version of DB2 express and take

control of your XML. No limits. Just data. Click to get it now.

http://sourceforge.net/powerbar/db2/____________________________________
___________
<http://sourceforge.net/powerbar/db2/___________________________________
____________> 

Snort-users mailing list

Snort-users@lists.sourceforge.net
<mailto:Snort-users@lists.sourceforge.net> 

Go to this URL to change user options or unsubscribe:

https://lists.sourceforge.net/lists/listinfo/snort-users
<https://lists.sourceforge.net/lists/listinfo/snort-users> 

Snort-users list archive:

http://www.geocrawler.com/redir-sf.php3?list=snort-users
<http://www.geocrawler.com/redir-sf.php3?list=snort-users> 

 









-------------------------------------------------------------------------
This SF.net email is sponsored by DB2 Express
Download DB2 Express C - the FREE version of DB2 express and take
control of your XML. No limits. Just data. Click to get it now.
http://sourceforge.net/powerbar/db2/
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users
<Prev in Thread] Current Thread [Next in Thread>