AbeFroman

BANNED
Feb 16, 2002
644
1
318
I installed snort but it doesnt seem to be logging anything.

I run
snort -c snort.conf -i eth0 -D

But nothing gets logged:
mysql> use snort_db
Reading table information for completion of table and column names
You can turn off this feature to get a quicker startup with -A

Database changed
mysql> select * from event;
Empty set (0.00 sec)

I followed the instructions here:
http://www.floridahoneynet.org/whites/snortacid.html

This is what snort.conf reads
.
.
.
# database: log to a variety of databases
# ---------------------------------------
# See the README.database file for more information about configuring
# and using this plugin.
#
output database: log, mysql, user=snort_snort password=snortpassword dbname=snort_db host=localhost
# output database: alert, postgresql, user=snort dbname=snort
# output database: log, odbc, user=snort dbname=snort
# output database: log, mssql, dbname=snort user=snort password=test
# output database: log, oracle, dbname=snort user=snort password=test
.
.
.

I have verified snort is running:
[email protected] [~/snort-2.2.0/etc]# ps -e | grep snort
25685 ? 00:00:00 snort


Got any tips?