engarde-users March 2003 archive
Main Archive Page > Month Archives  > engarde-users archives
engarde-users: [EnGarde] Re: Snort with mysql issues

[EnGarde] Re: Snort with mysql issues

From: Rhoton, Casey <CRhoton_at_nospam>
Date: Fri Mar 14 2003 - 14:40:18 GMT
To: "'engarde-users@engardelinux.org'" <engarde-users@engardelinux.org>

        Tried this work around, to no avail. Thanks for the idea, I may have to use logsnorter to parse the log file and write the data to the database. Anyone have any other ideas?

Casey Rhoton
Network Security Engineer
IPC Technologies

-----Original Message-----
From: Serge Leschinsky [mailto:fish@artlife.tomsknet.ru] Sent: Friday, March 14, 2003 12:44 AM
To: Rhoton, Casey
Subject: [EnGarde] Re: Snort with mysql issues

Dear Casey.

On Thursday, March 13, 2003, at 12:19 GMT -05   (23:19, the same day my local time),
 you wrote about "[EnGarde] Snort with mysql issues", at least in part:

RC> Has anyone run snort with mysql on Engarde? Unfortunately I've not. RC> I have upgraded to the RC> latest Snort package, and cannot get the connection to mysql working. Is RC> this due to the chrooted environment locking snort down to said environment?
 I think you are right. Try to do something like the following: mkdir /var/chroot/snort/var/lib/mysql
ln /var/lib/mysql/mysql.sock /var/chroot/snort/var/lib/mysql/mysql.sock

If it helps, you have to recreate hard link every time mysql restarts. -- Yours sincerely Serge Leschinsky mailto:fish@artlife.tomsknet.ru
------------------------------------------------------------------------
To unsubscribe email engarde-users-request@engardelinux.org with "unsubscribe" in the subject of the message.
------------------------------------------------------------------------
To unsubscribe email engarde-users-request@engardelinux.org with "unsubscribe" in the subject of the message.