LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-27-2002, 12:35 AM   #1
bripage
Member
 
Registered: Jan 2002
Location: Moorpark
Distribution: SLACK 8!
Posts: 230

Rep: Reputation: 30
Snort to log ALL packets, and print them to the console?!?


Im trying to get snort to log ALL the packets that pass over my network at one point or another, and then also print them to the screen. I cant seem to figure out how to do this.. Ive tried the man pages.. and even the readme. Stupid noob.
 
Old 09-27-2002, 05:47 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Hmm. I'd suggest you log them to file and tail it from there, because if you only print them on screen you won't have logs for looking at it later. Logfile location is set at compile time, then "tail -vf </location/logfilename> >> /dev/tty#" where # is the tty number you want it to appear at.

Logging *everything* in and having to decode it and save it in human readable text format makes snort slower. So you'll have to scrub the conf file for rulesets you don't use, or try unified logging format and run barnyard as a decoder.
 
Old 09-27-2002, 12:36 PM   #3
bripage
Member
 
Registered: Jan 2002
Location: Moorpark
Distribution: SLACK 8!
Posts: 230

Original Poster
Rep: Reputation: 30
Ok... Well... I have Snort installed already. Now i need to know how get the two progs running together. I asume that barnyard runs off snorts out plugins, but how do I tailor them to fit snort? And, I dont even know if I have snort setup correctly. When I turn it on, all I get are some TCPdump messages (few) and the rest i get are AR requests.
 
Old 09-27-2002, 05:11 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Could you rephrase your questions clearly, state what you've done, what won't work and show some error (logs) for it?
I mean "when I turn it on" usually refers to you coercing the application to do something by chanting some commandline arguments, "tailor them to fit snort" could well mean you would like to recode the snort output plugins to your liking, and assuming, well, you know what they say :-]
 
Old 09-30-2002, 09:58 PM   #5
neo77777
LQ Addict
 
Registered: Dec 2001
Location: Brooklyn, NY
Distribution: *NIX
Posts: 3,704

Rep: Reputation: 56
snort -dev -l /where/to/log
you might also want -i flag to specify an interface (eth0, eth1, ppp0, etc) and -c to specify the config file for snort is also a good option if you want to use a custom configuration file + rules, rules, and latest rules. the documentation at snort home website is suprior IMHO.
 
Old 10-01-2002, 08:40 AM   #6
jeremy
root
 
Registered: Jun 2000
Distribution: Debian, Red Hat, Slackware, Fedora, Ubuntu
Posts: 13,602

Rep: Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084
bripage, you really are using the wrong program for what you are trying to do. Try Ethereal - http://www.ethereal.com/

--jeremy
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
tcpdump and snort cannot filter PPPoE packets kaito Linux - Networking 8 08-16-2009 03:25 AM
log dropped packets from queue exeon Linux - Networking 2 03-26-2005 09:36 AM
I can't get snort to log anything abefroman Linux - Security 2 09-07-2004 09:09 AM
Is it possible to log packets in/out of a specific port? jon_k Linux - Software 5 08-12-2004 06:07 AM
Snort is not log chamkila Linux - Security 19 06-18-2003 02:30 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:41 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration