The problem is the database file for MySQL. I set it following the direction set out by Patrick Harper which were prefect for me. Any way his direction are for snort-2.1.0 and we are now one Snort-2.3. The file that is supposed to be used to create the extra databases for MySQL is no longer included in this version of snort. I downloaded the file from Snort.org and applied it per the directions but when I launch BASE i get this error:
The underlying database snort@localhost appears to be incomplete/invalid
Database ERROR:Table 'snort.iphdr' doesn't exist
It might be an older version. Only alert databases created by Snort 1.7-beta0 or later are supported
I can't seem to find any ref. to this issue but the file in question is snortdb-extra.gz
any thoughts.
|