[Snort-users] alert file, database output?!?!

Federico Lombardo egopfe at ...125...
Wed Jan 15 08:46:49 EST 2003


Hi all, I've a little problem configuring log output.

I wanna log my alert into a mysql database, so let's configure snort.conf
such as:

include ../rules/classification.config

include ../rules/reference.config

preprocessor http_decode: 80 443 3128 8080 unicode iis_alt_unicode
double_encode iis_flip_slash full_whitespace

preprocessor frag2: 16777216, 30

preprocessor stream4: memcap 16777216, detect_state_problems

preprocessor stream4_reassemble: serveronly 21 23 25 53 80 110 111 143 443
513 1433 2138 2255 5631 8080

preprocessor rpc_decode: 111

preprocessor bo: -nobrute

preprocessor portscan: $HOME_NET 4 3 portscan.log

preprocessor portscan-ignorehosts: 212.17.192.49 194.247.160.6 212.17.192.49
194.73.95.85 198.41.0.10 212.216.112.112 212.245.255.2 194.20.8.4

preprocessor arpspoof

preprocessor telnet_decode

# LOGGING

ruletype clear

{

type pass output

output database: alert, mysql, user=snort dbname=snort_alert
host=192.168.0.2 password= sensor_name=fwint0  detail=full

}

ruletype normal

{

type alert output

output database: alert, mysql, user=snort dbname=snort_alert
host=192.168.0.2 password= sensor_name=fwint0

detail=full

}



ruletype redalert

{

type alert output

output database: alert, mysql, user=snort dbname=snort_alert
host=192.168.0.2 password= sensor_name=fwint0 detail=full

output trap_snmp: alert, 4, inform -v 2c -p 163 192.168.0.3 public

}

ruletype archivio

{

type log output

output database: log, mysql, user=snort dbname=snort_log host=192.168.0.2
password= sensor_name=fwint0 detail=full

}



Now i can't manage why into my /var/log/snort/ snort creates an alert file
containing alerts... instead of sending them to the database... why ???

Also, how I can make snort stop to log BAD Packets ? which preprocessor ?



Thank in advance,

Federico




More information about the Snort-users mailing list