[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: snort



Hi!

I've figured out the problem. There is a script in cron.daily called
5snort and it searches /var/log/auth.log for snort reports, not
/var/log/snort/sth. Therefore you need to have snort configured to send
alert messages also to syslog. You have to edit /etc/init.d/snort and add
an '-s' option into it. And now it works.

Is this a bug? I haven't noticied anything about that in stable package's
documentation.


<quote who="Joost De Cock">
> On Monday 08 March 2004 13:27, Nejc Novak shoved this in my mailbox:
>> Hi!
>> I have installed snort on debian stable. Snort sends me e-mail report, but
>> it is empty. I believe it has sth to do with logrotate, but i don't
know
>> how to fix it. Help please.
>
> Check in your crontab what is sending you the email (probably
> in /etc/cron.daily).
> Once you find out you can run the script manually and see what goes
wrong.






Reply to: