[Snort-users] Sensor agent in SnortCenter

David Powell dpowell at ...8963...
Mon May 5 11:57:07 EDT 2003


Anybody using SnortCenter?  

Strange issue, not SnortCenter related actually so anyone may have had this
issue before.  

I've setup my output plug-in correctly because I've got two other sensors
working fine.  

The third sensor I'm attempting to add is giving me a mysql connection
error.  I've made this sensor just like the rest.  

I can get SnortCenter to connect the sensor and push rules to the sensor
just fine but when I try to start the sensor I get this message;

IP's and names have been changed of course,
All three sensors are inside network sensors.  No outside interfaces.

Current config file error:
Running in IDS mode
Log directory = /var/log/snort

Initializing Network Interface eth1

--== Initializing Snort ==--
Rule application order changed to Pass->Alert->Log
Initializing Output Plugins!
Decoding Ethernet on interface eth1
Parsing Rules file /etc/snort/snort.eth1.conf

+++++++++++++++++++++++++++++++++++++++++++++++++++
Initializing rule chains...
Initializing Preprocessors!
Initializing Plug-ins!
No arguments to frag2 directive, setting defaults to:
Fragment timeout: 60 seconds
Fragment memory cap: 4194304 bytes
Fragment min_ttl: 0
Fragment ttl_limit: 5
Fragment Problems: 0
Self preservation threshold: 500
Self preservation period: 90
Suspend threshold: 1000
Suspend period: 30
Stream4 config:
Stateful inspection: ACTIVE
Session statistics: INACTIVE
Session timeout: 30 seconds
Session memory cap: 8388608 bytes
State alerts: INACTIVE
Evasion alerts: INACTIVE
Scan alerts: ACTIVE
Log Flushed Streams: INACTIVE
MinTTL: 1
TTL Limit: 5
Async Link: 0
State Protection: 0
Self preservation threshold: 50
Self preservation period: 90
Suspend threshold: 200
Suspend period: 30
Stream4_reassemble config:
Server reassembly: INACTIVE
Client reassembly: ACTIVE
Reassembler alerts: ACTIVE
Ports: 21 23 25 53 80 110 111 143 513 1433 
Emergency Ports: 21 23 25 53 80 110 111 143 513 1433 
http_decode arguments:
Unicode decoding
IIS alternate Unicode decoding
IIS double encoding vuln
Flip backslash to slash
Include additional whitespace separators
Ports to decode http on: 80 
rpc_decode arguments:
Ports to decode RPC on: 111 32771 
alert_fragments: INACTIVE
alert_large_fragments: ACTIVE
alert_incomplete: ACTIVE
alert_multiple_requests: ACTIVE
telnet_decode arguments:
Ports to decode telnet on: 21 23 25 119 
Conversation Config:
KeepStats: 0
Conv Count: 32000
Timeout : 60
Alert Odd?: 0
Allowed IP Protocols: All

ERROR: database: mysql_error: Can't connect to MySQL server on '10.x.x.x'
(110)
Fatal Error, Quitting..
database: compiled support for ( mysql )
database: configured to use mysql
database: user = xxxx
database: password is set
database: database name = xxxx
database: host = 10.x.x.x
database: sensor name = snort3
database: detail level = full  

Dave Powell - Network Analyst
Infrastructure 310-258-7140
Herbalife IT Department






More information about the Snort-users mailing list