Quote:
Originally Posted by unSpawn
No, not without diagnostics. What is in the log output? And Snort statistics?
You need Barnyard if you log to binary format (binary format being way faster compared to text format logs).
|
Thanks! I was logging in regular format and tried with barnyard installed.
I think something in my /etc/my.cnf file fubarred it, and/or I needed to add this line:
wait_timeout = 10000000
New items are showing up in BASE now:
[local] [snort] WEB-MISC /~root access attempted-recon 1(14%) 1 1 1 2008-04-28 21:28:42 2008-04-28 21:28:42
The error in the log file was:
# cat /var/log/messages |grep has\ gone\ away
Apr 28 21:25:59 lds185 snort[4386]: database: mysql_error: MySQL server has gone away SQL=UPDATE sensor SET last_cid = 4 WHERE sid = 1