Snortd Syslog Events Not Forwarding
I have Snort set up on CentOS6, configured to forward to a syslog server:
output alert_syslog: host=x.x.x.x:514, LOG_LOCAL7 LOG_INFO
rsyslog.conf
*.* @x.x.x.x:514
Where x.x.x.x is my syslog server
When I start Snort via the command line everything forwards fine to my syslog server
snort -c /etc/snort/snort.conf -i eth1
However, when I run /etc/init.d/snortd start my events don't forward to the syslog server.
I have tried disabling SELinux and no luck.
What am I missing?
Thanks.
|