[Snort-users] Re: Log vs Alert

Dusty Hall halljer at ...8709...
Thu Jun 26 14:06:04 EDT 2003


  Take a look at Snort's switches.... I think "snort -N ...." might
help you out.


>>> "John Deagan" <johndeaganaka at ...125...> 6/26/2003 1:49:20 PM >>>
How about this?  I want to write alerts to the database but nothing at
in text.

output database: alert, mysql, user= password= dbname= host=
output log_null

This will make it so I dont have to worry about that damn 
/var/log/snort/alert file.  But this
output database: log, mysql, user= password= dbname= host=
output log_null

Doesnt seem to work, /var/log/snort/alert still appears and gets big
slows down snort.  Why does this work for output database: alert but
database: log?

<<< John >>>

Add photos to your messages with MSN 8. Get 2 months FREE*.  

This SF.Net email is sponsored by: INetU
Attention Web Developers & Consultants: Become An INetU Hosting
Refer Dedicated Servers. We Manage Them. You Get 10% Monthly
INetU Dedicated Managed Hosting http://www.inetu.net/partner/index.php

Snort-users mailing list
Snort-users at lists.sourceforge.net 
Go to this URL to change user options or unsubscribe:
Snort-users list archive:

More information about the Snort-users mailing list