[Snort-users] Snort Test Error

Mike Koponick mike at ...7385...
Thu Jan 2 08:46:58 EST 2003


Hello all,

I hope everyone had a good New Year's.. now it's time to get some work done
;-)

I'm have an issue with SNORT. Over the holidays, the ACID database became
corupt somehow. So, I deleted the database, (I wasn't able to repait it) and
installed a new one, with the same files as the original.

Now, SNORT will not start. When testing it, I get the following output:

Testing Snort's ConfgurationInitializing Output Plugins!
Log directory = /var/log/snort

Initializing Network Interface eth1
WARNING: OpenPcap() device eth1 network lookup:
        eth1: no IPv4 address assigned

        --== Initializing Snort ==--
Decoding Ethernet on interface eth1
Initializing Preprocessors!
Initializing Plug-ins!
Parsing Rules file /etc/snort/snort.conf

+++++++++++++++++++++++++++++++++++++++++++++++++++
Initializing rule chains...
No arguments to frag2 directive, setting defaults to:
    Fragment timeout: 60 seconds
    Fragment memory cap: 4194304 bytes
    Fragment min_ttl:   0
    Fragment ttl_limit: 5
    Fragment Problems: 0
Stream4 config:
    Stateful inspection: ACTIVE
    Session statistics: INACTIVE
    Session timeout: 30 seconds
    Session memory cap: 8388608 bytes
    State alerts: INACTIVE
    Evasion alerts: INACTIVE
    Scan alerts: ACTIVE
    Log Flushed Streams: INACTIVE
    MinTTL: 1
    TTL Limit: 5
    Async Link: 0

*WARNING*: unknown preprocessor "stream4_reassemble, ports all", ignoring!

http_decode arguments:
    Unicode decoding
    IIS alternate Unicode decoding
    IIS double encoding vuln
    Flip backslash to slash
    Include additional whitespace separators
    Ports to decode http on: 80
rpc_decode arguments:
    Ports to decode RPC on: 111 32771
telnet_decode arguments:
    Ports to decode telnet on: 21 23 25 119
Using LOCAL time
Conversation Config:
   KeepStats: 0
   Conv Count: 32000
   Timeout   : 60
   Alert Odd?: 1
   Allowed IP Protocols:
Portscan2 config:
    log: /var/log/snort/scan.log
    scanners_max: 3200
    targets_max: 5000
    target_limit: 5
    port_limit: 20
    timeout: 60
WARNING => [Alert_FWsam](FWsamCheckIn) Could not connect to host
192.168.xx.xx. Will try later.
database: compiled support for ( mysql )
database: configured to use mysql
database:          user = snort
database: password is set
database: database name = snort
database:          host = localhost
database:   sensor name = snort:eth1
database:     sensor id = 2
database: schema version = 0
database: The underlying database seems to be running an older version of
          the DB schema (current version=0, required minimum version= 106).

          If you have an existing database with events logged by a previous
          version of snort, this database must first be upgraded to the
latest
          schema (see the snort-users mailing list archive or DB plugin
          documention for details).

          If migrating old data is not desired, merely create a new instance
          of the snort database using the appropriate DB creation script
          (e.g. create_mysql, create_postgresql, create_oracle,
create_mssql)
          located in the contrib\ directory.

          See the database documentation for cursory details
(doc/README.database).
          and the URL to the most recent database plugin documentation.
Fatal Error, Quitting..

As far as I know, it's all the same files that I have been using in the
past.

Anyone have any ideas?

Thanks in advance,

Mike





More information about the Snort-users mailing list