how can I tell snort is running and logging alerts?
i was wondering if anybody can point me in the right direction.
i have a new install of snort 2.1, sensor, ACID, and snortcenter running on the same box...Fedora redhat. When the sensor is running i use another box to connect to the ACID console to view alerts, etc… however nothing shows up in ACID. No alter etc...
When i start snort in /etc/snort i get no error messages, everything seems to run fine. Also the rule files are in the same directory \etc\snort
for some reason the alerts don't get logged in /var/log/snort i checked the snort.conf file where i make the database connection and all looks good yet nothing gets logged. HELP
PS when i setup a test rule in snort.conf, ACID sees it when i start snort, but the alerts in the default rules don't get logged to /var/log/snort
Does this make sense?