[Snort-users] why is gid missing from the db schema ?
Yarden Livnat
yarden at ...3027...
Tue Nov 23 19:41:47 EST 2004
I noticed that in the 'signature' table of the database schema only the
sid and rev field are set from the snort event but the gid (generator
id) is ignored and thus can not be recovered from the database.
why is this ? is there another way of recovering the gid ?
I'm writing a visualization system that uses the data from the database
but the missing 'gid' is a real headache.
thanks,
Yarden
p.s. I check the 'C' code and sure enough it ignore the sig_generator
from the event field.
More information about the Snort-users
mailing list