Snort sensor is not showing in ACID?
Posted on 2004-10-13
I am new to Snort so I maight be not seeing something very basic.
I am running Snort on Windows 2000 Professional.
That is Snort 2.2.0, Acid 0.9.6b, Adodb 4.5.2, PHP 4.3.9, Mysql 4.0.21, Winpcap 3.0
When I run Snort (snort –v) Acid is showing that sensor = 0 ?? Why is this?
In the same time I can tell that Snort is running, it is showing it’s activity in DOS and in Task Manager.
Snort.conf “var HOME_NET” VARIABLE is set to “any”.
I did all the configuration as required except I did not edit adodb configuration file but not sure if this is connected with the problem. I red that this version of Adodb doesn’t need editing but finds adodb path automatically.
Is Winpcap misbehaving? Ther is an error at the end of Snort report. I will include Snort output bellow:
“Snort received 1671 packets
Breakdown by protocol:
TCP: 33 (1.975%)
UDP: 8 (0.479%)
ICMP: 1626 (97.307%)
ARP: 2 (0.120%)
EAPOL: 0 (0.000%)
IPv6: 0 (0.000%)
IPX: 0 (0.000%)
OTHER: 0 (0.000%)
DISCARD: 0 (0.000%)
10/13-15:05:50.897424 172.16.10.1 -> Action Stats:
ICMP TTL:128 TOS:0x0 ID:4062 IpLen:20 DgmLen:60
Type:8 Code:0 ID:768 Seq:33541 ECHO
10/13-15:05:50.897475 172.16.10.2 -> 172.16.10.1
ICMP TTL:128 TOS:0x0 ID:17140 IpLen:20 DgmLen:60
Type:0 Code:0 ID:768 Seq:33541 ECHO REPLY
pcap_loop: read error: PacketReceivePacket failed
Run time for packet processing was 428.446000 seconds”
Would you have any idea why is sensor not showing in ACID?
Thanks a lot,