[Snort-users] snorby, squert, BASE and sguil stopped except Snort

Doug Burks doug.burks at ...11827...
Wed Aug 29 10:53:18 EDT 2012


Hello Dai,

Since you say this isn't a snort-specific problem, we should probably
troubleshoot this over on the Security Onion mailing list:
http://groups.google.com/group/security-onion

Please include the output of the following:
sudo sostat
(redacting sensitive info as necessary)

Thanks,
Doug

On Wed, Aug 29, 2012 at 10:27 AM, daisung choi <choi.daisung at ...11827...> wrote:
> Hi all,
>
> Snort and barnyard2 are running and it creates data properly. But when I
> access to Snorby, Squert, BASE or Sguil, none of them display any alerts.
>
> I am using Security Onion and /nsm/sensor_data/computer-desktop-eth1#/
> contains today's alert messages so I am sure that the Snort is not a
> problem.
>
> what should I check?
>
> Thanks in advance,
>
> Dai
>
> ------------------------------------------------------------------------------
> Live Security Virtual Conference
> Exclusive live event will cover all the ways today's security and
> threat landscape has changed and how IT managers can respond. Discussions
> will include endpoint security, mobile security and the latest in malware
> threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users
>
> Please visit http://blog.snort.org to stay current on all the latest Snort
> news!



-- 
Doug Burks
http://securityonion.blogspot.com




More information about the Snort-users mailing list