[Snort-users] Oracle Database Table Explanation

roman at ...438... roman at ...438...
Fri Jun 1 13:12:52 EDT 2001


> Snort is adding stuff to the IPHDR,ICMPHDR,IPHDR,TCPHDR and UDPHDR files
> respectively.

Any chance that the permission on the "event" table do not
have INSERT priviledge for the snort db user?

Are there any error messages generated by Snort?

Try recompiling Snort in DEBUG mode to get extra diagnostics
to see where the logging is failing. 
(i.e. make clean; make  "-DDEBUG")

Roman


> 
> -----Original Message-----
> From: roman at ...438... [mailto:roman at ...438...]
> Sent: Tuesday, May 29, 2001 12:11 PM
> To: rseals at ...2137...
> Cc: snort-users at lists.sourceforge.net
> Subject: Re: [Snort-users] Oracle Database Table Explanation
> 
> 
> Ray,
> 
> > When snort generates
> > a detect it puts the header files into the appropriate tables but I never
> > get the snort_events table updated.
> 
> What version of Snort?
> 
> I'm not sure what you mean by this statement.  "Header files"?
> So is snort logging to the database or not?  A row should be
> added to the "event" table for every triggered alert.
> 
> > This table references a signatures
> > table but that table is empty also.
> 
> If both the signature and event table are empty then Snort
> is definitely not logging to the database?  Any entries in the
> "sensor" table?
> 
> Roman
> 
> 
> ---------------------------------------------
> This message was sent using Voicenet WebMail.
>       http://www.voicenet.com/webmail/
> 
> 
> 
> 
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> http://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users
> 
> 



---------------------------------------------
This message was sent using Voicenet WebMail.
      http://www.voicenet.com/webmail/






More information about the Snort-users mailing list