Snort - relatorios diarios em branco
Olá,
Alguém conhece o Snort (1.8.4beta1-3.1) rodando em Debian (kernel 2.4.18-1-586tsc) e saberia me dizer por que ele está me mandando o "daily report" em branco, apesar de estar logando normalmente em /var/log/snort?
# ls -l /var/log/snort/alert*
-rw------- 1 snort snort 8009644 Jul 25 17:16 /var/log/snort/alert
# cat /etc/snort/snort.debian.conf
...
DEBIAN_SNORT_STARTUP=boot
DEBIAN_SNORT_HOME_NET="xxx" <rede/máscara de eth1 - corretos>
DEBIAN_SNORT_OPTIONS=" -i eth1" <a interface do firewall q interessa>
DEBIAN_SNORT_STATS_RCPT="xxx@mg.trt.gov.br" <meu endereço eletrônico>
DEBIAN_SNORT_STATS_TRESHOLD="1"
Ou seja, parece estar tudo ok.
Alguma dica?
[]s,
Gustavo
__________________________________________________________________
McAfee VirusScan Online from the Netscape Network.
Comprehensive protection for your entire computer. Get your free trial today!
http://channels.netscape.com/ns/computing/mcafee/index.jsp?promo=393397
Get AOL Instant Messenger 5.1 free of charge. Download Now!
http://aim.aol.com/aimnew/Aim/register.adp?promo=380455
Reply to: