[Snort-users] why is gid missing from the db schema ?

Yarden Livnat yarden at ...3027...
Tue Nov 23 19:41:47 EST 2004


I noticed that in the 'signature' table of the database schema only the 
sid and rev field are set from the snort event but the gid (generator 
id) is ignored and thus can not be recovered from the database.

why is this ? is there another way of recovering the gid ?

I'm writing a visualization system that uses the data from the database 
but the missing 'gid' is a real headache.

thanks,

	Yarden

p.s. I check the 'C' code and sure enough it ignore the sig_generator 
from the event field. 





More information about the Snort-users mailing list