[Snort-users] logging appears to have slowed down dramitically

Andrew P. Kaplan noc at ...6853...
Sun Sep 8 11:40:03 EDT 2002


I just setup snort using "twigles" excellent how-to. I'm not logging to
mysql yet. Just want to get a feel for snort first.
Using snort -c /usr/snort/snort.conf -l /var/log/snort -s

I noticed a hundreds of directories created under /var/log/snort for the
first 24 hours. However in day 2,3,4,and 5 only one or two directories are
being created per day. Plus when I view the older directories they don't
show any new activity, as they should since some of the boxes are MY boxes
creating FP's.

[=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-]
  Andrew P. Kaplan	             Network Administrator
  WEB	www.cshore.com                 168 Boston Post Road
  EMAIL: noc at ...6853...              Madison, CT 06443
[=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-]



Obstacles are those things that appear when you lose sight of your
goal.
                     -  Henry Ford








---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.385 / Virus Database: 217 - Release Date: 9/4/02





More information about the Snort-users mailing list