[Snort-users] Applying a rule on entire session
Mohammad Abdel Hady
mohammad_hady at ...12130...
Wed Sep 8 01:45:29 EDT 2004
I have a problem in installing Snort 2.1.3 on my SQL because every time I installing it I got the same error
1- The snort Data base that I created on the MYSQL always doesn't have tables or columns
2- This error in the Event Viewer (event ID 1) and its description is
When this plug-in starts, a SLECT query is run to find the sensor id for the currently running sensor. If the Sensor id is not found, the plug-in will run an INSERT query to insert the proper data and generate a new sensor id. Then a SELECT query is run to get the newly allocated sensor id, if that fails then this error message is generated.
Some possible causes for this error
* The user doesn't have the proper INSERT or SELECT Privileges
* The Sensor Table doesn't exist.
So Please I need your Support in
From: Alex Butcher, ISC/ISYS [mailto:Alex.Butcher at ...11254...]
Sent: Wednesday, 08 September, 2004 10:45 AM
To: Dennis George; snort-users at lists.sourceforge.net
Subject: Re: [Snort-users] Applying a rule on entire session
--On 07 September 2004 20:48 -0700 Dennis George <easyeinfo at ...131...>
> Hi all,
> Is it possible to apply a particular rule only after catching the entire
> session, not on every packet............ ??
flowbits and looking for the FIN and/or RST flags?
> Thanks in advance........
Alex Butcher: Security & Integrity, Personal Computer Systems Group
Information Systems and Computing GPG Key ID: F9B27DC9
GPG Fingerprint: D62A DD83 A0B8 D174 49C4 2849 832D 6C72 F9B2 7DC9
This SF.Net email is sponsored by BEA Weblogic Workshop
FREE Java Enterprise J2EE developer tools!
Get your free copy of BEA WebLogic Workshop 8.1 today.
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:
More information about the Snort-users