[Snort-users] Problems logging to syslog and mysql simultaneously

Michael Steele michaels at ...155...
Wed Jun 19 15:12:04 EDT 2002


Dallas,

Remove the -s switch and add these to your Snort.conf

output alert_syslog: LOG_AUTH LOG_ALERT
output alert_full

-Michael
--
 Michael Steele | System Engineer / Support Technician
 mailto:michaels at ...155...
 Silicon Defense: IDS solutions - http://www.silicondefense.com
 Snort: Open Source Network IDS - http://www.snort.org



-----Original Message-----
From: snort-users-admin at lists.sourceforge.net
[mailto:snort-users-admin at lists.sourceforge.net] On Behalf Of
dlpassport at ...6137...
Sent: Wednesday, June 19, 2002 2:46 PM
To: snort-users at lists.sourceforge.net
Subject: RE: [Snort-users] Problems logging to syslog and mysql
simultaneously

I'm still experiencing the same problem logging to a local syslog, even
with
the database logging disabled... it will only write there if i specify
the -s 127.0.0.1.  I've got a feeling I'm missing something obvious.
Any
suggestions?


Thanks,
DL


-----Original Message-----
From: Michael Steele [mailto:michaels at ...155...]
Sent: Wednesday, June 19, 2002 2:26 PM
To: dlpassport at ...6137...
Cc: snort-users at lists.sourceforge.net
Subject: RE: [Snort-users] Problems logging to syslog and mysql
simultaneously

Dallas,
You need to pickup a syslog server like Kiwi Syslog Server or a freeware
one:
Snip--Snip ->
For stability I would recommend 3com's free syslog server for Windowz
http://support.3com.com/software/utilities_for_windows_32_bit.htm <--
for a bunch of goodies
ftp://ftp.3com.com/pub/utilbin/win32/3CSyslog.zip <-- for the syslog
server
It runs great on 2K & XP
This one may work:
http://www.cls.de/Default.asp
works well but randomly inserts fixed string in syslog output in
the freeware version.
<--snip-->
Hello list. I am running Snort 1.8.7-mysql-win32 and am having the
following problem.
I would like to log to the local mysql database as well as a remote
syslog.


More information about the Snort-users mailing list