Snort - sending messages to MySQL on another Snort machine
Posted on 2006-10-27
I have W2K running Snort 2.4.5 and RHEL4 running Snort 188.8.131.52, both in IDS mode. The windows system is logging to syslog and the rhel system is logging to a mysql database. Both are working fine. . . I am running base on the rhel system.
I cant figure out how to have the alerts on the windows system go to the mysql data base on the linux system. I configured an output database command and the windows system is getting alerts (they show on the DOS console) but when I trace the connection between the two systems, no data ever leaves the windows system.
I am new to snort and relatively new to rhel . . . there must be a way to send data/alerts from multiple sensors. Any ideas?