[Snort-users] stripped-down snort/mysql for newbie

Erek Adams erek at ...577...
Thu Jul 25 18:15:03 EDT 2002


On Thu, 25 Jul 2002, joe van wrote:

> Hello, all.  I got the IDS R&D project at work and I figured that the pig
> was just as good as any commercial distribution w/o having to spend 20
> large.
>
> I'm trying to get Snort installed/configured on a pair of pc's running RH
> 7.2 Linux.  Now, I know there is an installation guide for RH 7.2 in the
> Snort docs, but I think it might be getting in the way of my basic
> understanding of what Snort does.  I just wanna set up the sensor on one
> machine, the mysql db on the other, and that's it.
>
> I'd love to add in some of the other bells n' whistles ...later.  Now I just
> wanna see how the basic product works w/o the Acid, webmin, apache, and so
> on.
>
> Is there a doc for such a stripped-down install, or can I merely disregard
> all the references to the other goodies in the doc?

Joe,

	If you aren't using a 'frontend' like ACID, the mysql might be a bit
of overkill.  Esp. if you're just doing testing.  You might want to consider
just installing snort and checking out the log files instead of logging to a
db.  I'm just a big fan of the Keep it Simple school.  :)

	Cheers!

-----
Erek Adams
Nifty-Type-Guy
TheAdamsFamily.Net





More information about the Snort-users mailing list