Solved

Snort - sending messages to MySQL on another Snort machine

Posted on 2006-10-27
6
350 Views
Last Modified: 2010-04-11
I have W2K running Snort 2.4.5 and RHEL4 running Snort 2.6.0.2, both in IDS mode. The windows system is logging to syslog and the rhel system is logging to a mysql database. Both are working fine. . . I am running base on the rhel system.

I cant figure out how to have the alerts on the windows system go to the mysql data base on the linux system. I configured an output database command and the windows system is getting alerts (they show on the DOS console) but when I trace the connection between the two systems, no data ever leaves the windows system.

I am new to snort and relatively new to rhel . . . there must be a way to send data/alerts from multiple sensors. Any ideas?
0
Comment
Question by:SteveJ
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
6 Comments
 
LVL 9

Accepted Solution

by:
crawfordits earned 100 total points
ID: 17824508
set the mysql output-logging in the snort.conf to get some debugging action.. then paste back output.. its possible it will output something like " Host 'x.x.x.x' is not allowed to connect to this MySQL server" then it it obvious what to do
0
 
LVL 9

Expert Comment

by:crawfordits
ID: 17824509
dont forget snort -T
0
 
LVL 16

Author Comment

by:SteveJ
ID: 17824656
Turns out that I didn't have a sensor_name variable on the sensor OR the main machine. When I added the sensor_name to the main machine it was visible in BASE and all's working fine now.

Thanks for responding crawfordits . . . the other problem is that I have Red Hat Advance Server 4 and it's got old PHP (4.0.x) and old MySQL (3.x) and I can't get pear to work . . . I'm a novice at red hat and I can't figure out how to upgrade all the stuff that it complains about when I try to upgrade the RPM and glibc and on and on . . .
0
 
LVL 38

Assisted Solution

by:Rich Rumble
Rich Rumble earned 100 total points
ID: 17828333
Try using Yum, aptget or uo2date:
as root
yum update php     or yum update mysql   or... yum update (then copy the packages you want to update to the command "yum update package1 package2 package3.."

iI think up2date is installed by default, yum might not be available
-rich
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Smart phones, smart watches, Bluetooth-connected devices—the IoT is all around us. In this article, we take a look at the security implications of our highly connected world.
No single Antivirus application (despite claims by manufacturers) will catch or protect you from all Virus / Malware or Spyware threats. That doesn't stop you from further protecting yourself however - and this article is to show you how.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question