LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-28-2003, 06:49 AM   #1
fotoguy
Senior Member
 
Registered: Mar 2003
Location: Brisbane Queensland Australia
Distribution: Custom Debian Live ISO's
Posts: 1,291

Rep: Reputation: 62
Snort Log Files Question


I'm new to snort and i think that i have it set up right, i just have a few questions about the log files. Snort is logging to /var/log/snort directory, i have the ip addresses of my network machines showing up as folders, is this supposed to happen. Plus there are 2 other ip's i don't know 239.255.255.250 and 255.255.255.255 are they network broadcast?. Also my log files are being log like snort.log.1072483058, snort.log.1072496953, this is the same for suspicious.log and tcpdump.log. Can i have these logged as 1 file each for that day with the date in the file name.

thanks
 
Old 01-03-2004, 06:02 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
the ip addresses of my network machines showing up as folders, is this supposed to happen.
Depends on how you configure Snort.


Plus there are 2 other ip's i don't know 239.255.255.250 and 255.255.255.255 are they network broadcast?.
Could be and yes.


Also my log files are being log like snort.log.1072483058, snort.log.1072496953, this is the same for suspicious.log and tcpdump.log. Can i have these logged as 1 file each for that day with the date in the file name.
No, not that I know of.
 
Old 01-04-2004, 12:17 AM   #3
fotoguy
Senior Member
 
Registered: Mar 2003
Location: Brisbane Queensland Australia
Distribution: Custom Debian Live ISO's
Posts: 1,291

Original Poster
Rep: Reputation: 62
Thanks for that, i've been doing a bit more reading and research since I posted the question
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
snort log file question ziegen Linux - Security 9 08-19-2004 02:49 PM
Question on Apache Log Files JLDixon Linux - Software 1 10-12-2003 11:03 AM
Question about log files... WeNdeL Linux - Newbie 1 02-13-2003 11:36 AM
Question about 2 files in /var/log jimmmac Linux - Newbie 4 01-26-2003 07:19 PM
Interpreting Snort log files and alerts epeus Linux - Security 6 10-21-2002 09:47 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:32 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration