We help IT Professionals succeed at work.

We've partnered with Certified Experts, Carl Webster and Richard Faulkner, to bring you a podcast all about Citrix Workspace, moving to the cloud, and analytics & intelligence. Episode 2 coming soon!Listen Now

x

Snort - sending messages to MySQL on another Snort machine

Steve Jennings
on
Medium Priority
371 Views
Last Modified: 2010-04-11
I have W2K running Snort 2.4.5 and RHEL4 running Snort 2.6.0.2, both in IDS mode. The windows system is logging to syslog and the rhel system is logging to a mysql database. Both are working fine. . . I am running base on the rhel system.

I cant figure out how to have the alerts on the windows system go to the mysql data base on the linux system. I configured an output database command and the windows system is getting alerts (they show on the DOS console) but when I trace the connection between the two systems, no data ever leaves the windows system.

I am new to snort and relatively new to rhel . . . there must be a way to send data/alerts from multiple sensors. Any ideas?
Comment
Watch Question

set the mysql output-logging in the snort.conf to get some debugging action.. then paste back output.. its possible it will output something like " Host 'x.x.x.x' is not allowed to connect to this MySQL server" then it it obvious what to do

Not the solution you were looking for? Getting a personalized solution is easy.

Ask the Experts
dont forget snort -T
Steve JenningsSr Manager Cloud Networking Ops
CERTIFIED EXPERT

Author

Commented:
Turns out that I didn't have a sensor_name variable on the sensor OR the main machine. When I added the sensor_name to the main machine it was visible in BASE and all's working fine now.

Thanks for responding crawfordits . . . the other problem is that I have Red Hat Advance Server 4 and it's got old PHP (4.0.x) and old MySQL (3.x) and I can't get pear to work . . . I'm a novice at red hat and I can't figure out how to upgrade all the stuff that it complains about when I try to upgrade the RPM and glibc and on and on . . .
Rich RumbleSecurity Samurai
CERTIFIED EXPERT
Top Expert 2006
Commented:
Try using Yum, aptget or uo2date:
as root
yum update php     or yum update mysql   or... yum update (then copy the packages you want to update to the command "yum update package1 package2 package3.."

iI think up2date is installed by default, yum might not be available
-rich
Access more of Experts Exchange with a free account
Thanks for using Experts Exchange.

Create a free account to continue.

Limited access with a free account allows you to:

  • View three pieces of content (articles, solutions, posts, and videos)
  • Ask the experts questions (counted toward content limit)
  • Customize your dashboard and profile

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.