LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices

Reply
 
LinkBack Search this Thread
Old 04-27-2008, 08:30 PM   #1
abefroman
Senior Member
 
Registered: Feb 2004
Location: Chicago
Distribution: CentOS w/Cpanel
Posts: 1,134

Rep: Reputation: 51
Snort not logging everything to the database


It seems snort is not logging everything to the database.

So far it has logged (output from BASE):
Sensors/Total: 1 / 1
Unique Alerts: 2
Categories: 2
Total Number of Alerts: 4

But from logging at the log files, it should have a lot more stuff in there:
-rw------- 1 snort snort 37533 Apr 27 20:18 alert
-rw------- 1 snort snort 49456 Apr 27 19:57 snort.log.1209342481
-rw------- 1 snort snort 13040 Apr 27 20:18 snort.log.1209344329

In /etc/snort/snort.conf I tried both log and alert for mysql.

Does anyone know why its not logging everything to the database?

Do I need to have barnyard installed?

Last edited by abefroman; 04-27-2008 at 09:39 PM.
 
Old 04-28-2008, 09:17 AM   #2
bigrigdriver
LQ Addict
 
Registered: Jul 2002
Location: East Centra Illinois, USA
Distribution: Debian Squeeze
Posts: 5,406

Rep: Reputation: 212Reputation: 212Reputation: 212
The best suggestion I can make is to make a google/linux search for snort logging articles, like this one.

Last edited by bigrigdriver; 04-28-2008 at 09:20 AM.
 
Old 04-28-2008, 09:58 AM   #3
abefroman
Senior Member
 
Registered: Feb 2004
Location: Chicago
Distribution: CentOS w/Cpanel
Posts: 1,134

Original Poster
Rep: Reputation: 51
Quote:
Originally Posted by bigrigdriver View Post
The best suggestion I can make is to make a google/linux search for snort logging articles, like this one.
Thanks! I have already done those steps though, those are just the standard instructions.
 
Old 04-28-2008, 03:28 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 21,610
Blog Entries: 47

Rep: Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413
Quote:
Originally Posted by abefroman View Post
Does anyone know why its not logging everything to the database?
No, not without diagnostics. What is in the log output? And Snort statistics?


Quote:
Originally Posted by abefroman View Post
Do I need to have barnyard installed?
You need Barnyard if you log to binary format (binary format being way faster compared to text format logs).
 
Old 04-28-2008, 09:33 PM   #5
abefroman
Senior Member
 
Registered: Feb 2004
Location: Chicago
Distribution: CentOS w/Cpanel
Posts: 1,134

Original Poster
Rep: Reputation: 51
Quote:
Originally Posted by unSpawn View Post
No, not without diagnostics. What is in the log output? And Snort statistics?



You need Barnyard if you log to binary format (binary format being way faster compared to text format logs).

Thanks! I was logging in regular format and tried with barnyard installed.

I think something in my /etc/my.cnf file fubarred it, and/or I needed to add this line:
wait_timeout = 10000000

New items are showing up in BASE now:
[local] [snort] WEB-MISC /~root access attempted-recon 1(14%) 1 1 1 2008-04-28 21:28:42 2008-04-28 21:28:42

The error in the log file was:
# cat /var/log/messages |grep has\ gone\ away
Apr 28 21:25:59 lds185 snort[4386]: database: mysql_error: MySQL server has gone away SQL=UPDATE sensor SET last_cid = 4 WHERE sid = 1
 
Old 04-29-2008, 07:54 AM   #6
unSpawn
Moderator
 
Registered: May 2001
Posts: 21,610
Blog Entries: 47

Rep: Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413
Thanks for what? I didn't do nothing. You fixed it all by yourself. Well done.

Last edited by unSpawn; 04-29-2008 at 07:59 AM.
 
Old 04-29-2008, 08:07 AM   #7
abefroman
Senior Member
 
Registered: Feb 2004
Location: Chicago
Distribution: CentOS w/Cpanel
Posts: 1,134

Original Poster
Rep: Reputation: 51
Quote:
Originally Posted by unSpawn View Post
Thanks for what? I didn't do nothing. You fixed it all by yourself. Well done.
By knowing it wasn't something major/common known issue, I knew I had to look for something minor. You and the other fellow helped point me in the right direction.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Problem Logging SNORT Data to Mysql Database ALInux Linux - Software 4 03-18-2008 12:16 PM
Snort database: Closing connection to database "" Homer Glemkin Linux - Security 2 07-14-2005 06:58 PM
snort logging to database ilnli Linux - General 14 04-08-2005 12:55 PM
Snort not logging Dogit Linux - Security 11 03-06-2005 03:22 PM
snort not logging? zuessh Linux - Security 9 05-30-2003 06:27 PM


All times are GMT -5. The time now is 03:20 AM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration