LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 08-28-2008, 01:48 PM   #1
eentonig
LQ Newbie
 
Registered: Jan 2008
Posts: 26

Rep: Reputation: 15
populating SNORT/ACIDLAB/ACIDBASE database with ulogd


Does anybody here uses ulogd in combination with ACIDBASE to log, monitor and report on dropped packets?

And how did you succeed in parsing your logged packets into the snort database?

I tried logsnorter-2.0, but although it doesn't give any error messages, it doesn't log anything.



I have 'iptables logs' running with ulogd, which inserts records into a ulogd database. But I find the output of 'iptables logs' a bit limited and crippled. So I wanted to use ACIDBASE which seems to be more developped. But it doesn't help me if I can't get the logging going.

Always willing to show the necessary configs if required.

Thanks,
 
Old 08-30-2008, 06:01 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
I don't understand. Maybe explain in detail what you mean by "limited and crippled" and what you expect or envision? I also don't understand how you intend to merge things. Snort logs packet data plus analysis data. So ACID, as an *analysis* engine, allows you to work on, interrogate, Snort logs for characteristics they both "know". Iptables output does not share the same characteristics. So how would you "translate" or fill fields in a way ACID can work with? If your requirement is just to have a web interface, like BASE bascially is, for querying a database, then shouldn't you be looking into existing solutions for that? I'm sure Freshmeat or Sourceforge should show some.
 
Old 08-31-2008, 04:28 AM   #3
eentonig
LQ Newbie
 
Registered: Jan 2008
Posts: 26

Original Poster
Rep: Reputation: 15
From the ACID website

Quote:
ACID has the ability to analyze a wide variety of events which are post-processed into its database. Tools exist for the following formats:

* using Snort (www.snort.org)
o Snort alerts
o tcpdump binary logs
* using logsnorter ( www.snort.org/downloads/logsnorter-0.2.tar.gz)
o ipchains
o iptables
o ipfw
Which, as I understand it, means that ACID can be used to analyze firewall events. To do this, it uses logsnorter to feed iptables events in the ACID database.

My problem is that logsnorter doesn't put anything in the ACID database. And, if nothing is being put in the database, ACID has nothing to analyze. As such, it's functionality is of no use.

I read on the snort website that logsnorter is currently no longer maintained. So I wanted to find out if there are new/other alternatives to get my logging into the ACID database. For example: ulogd is working perfectly for me to register all Firewall events in a MySQL datase, so I wondered if I could use ulogd to populate the ACID database.

So Basically.
- logsnorter isn't working for me. And currently I have no clue why not.
- I need a solution to get usefull information into ACID.
- Logsnorter is no longer maintained.

==> 1. Do I spent time on getting logsnorter to work? Where can I find info, troubleshooting assistance on it? Is it worth the effort, considering it's no longer maintained.
==> 2. Are there alternatives?
 
Old 08-31-2008, 05:26 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Ah, OK. Maybe check http://sourceforge.net/mailarchive/f...me=snort-users or post to snort-users@lists.sourceforge.net ?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Snort not logging everything to the database abefroman Linux - Software 6 04-29-2008 08:07 AM
Snort database: Closing connection to database "" Homer Glemkin Linux - Security 2 07-14-2005 06:58 PM
snort logging to database ilnli Linux - General 14 04-08-2005 12:55 PM
Snort Database Help roastmules Linux - Security 2 02-24-2005 01:05 PM
snort with mysql database zuessh Linux - Security 4 10-18-2004 12:36 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 04:27 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration