Snort Question



  • I am wondering if anyone else gets double entries from snort inside their system logs.  If you do, does anyone know how to turn off the double logging or get rid of it doing the double logging?

    Dec 8 18:44:44 	snort[62526]: [ Number of null byte prefixed patterns trimmed: 25829 ]
    Dec 8 18:44:44 	snort[62526]: [ Number of null byte prefixed patterns trimmed: 25829 ]
    Dec 8 18:44:44 	snort[62526]:
    Dec 8 18:44:44 	snort[62526]:
    Dec 8 18:44:44 	snort[62526]: --== Initialization Complete ==--
    Dec 8 18:44:44 	snort[62526]: --== Initialization Complete ==--
    Dec 8 18:44:44 	snort[62526]: Snort initialization completed successfully (pid=62526)
    Dec 8 18:44:44 	snort[62526]: Snort initialization completed successfully (pid=62526)
    Dec 8 18:44:44 	snort[62526]: Not Using PCAP_FRAMES
    Dec 8 18:44:44 	snort[62526]: Not Using PCAP_FRAMES
    


  • @LostInIgnorance:

    I am wondering if anyone else gets double entries from snort inside their system logs.  If you do, does anyone know how to turn off the double logging or get rid of it doing the double logging?

    Dec 8 18:44:44 	snort[62526]: [ Number of null byte prefixed patterns trimmed: 25829 ]
    Dec 8 18:44:44 	snort[62526]: [ Number of null byte prefixed patterns trimmed: 25829 ]
    Dec 8 18:44:44 	snort[62526]:
    Dec 8 18:44:44 	snort[62526]:
    Dec 8 18:44:44 	snort[62526]: --== Initialization Complete ==--
    Dec 8 18:44:44 	snort[62526]: --== Initialization Complete ==--
    Dec 8 18:44:44 	snort[62526]: Snort initialization completed successfully (pid=62526)
    Dec 8 18:44:44 	snort[62526]: Snort initialization completed successfully (pid=62526)
    Dec 8 18:44:44 	snort[62526]: Not Using PCAP_FRAMES
    Dec 8 18:44:44 	snort[62526]: Not Using PCAP_FRAMES
    

    how many interfaces are you monitoring?



  • Just my wan



  • @LostInIgnorance:

    Just my wan

    ok , i thought you might monitoring  two interfaces although pid sowing the same
    any way i checked at our system using 1.34 snort package its the same as you mention , its monitoring only the LAN int.

    Dec 10 09:34:14 	snort[32933]: +-------------------------------------------------
    Dec 10 09:34:14 	snort[32933]: [ Number of null byte prefixed patterns trimmed: 2382 ]
    Dec 10 09:34:14 	snort[32933]: [ Number of null byte prefixed patterns trimmed: 2382 ]
    Dec 10 09:34:14 	snort[32933]:
    Dec 10 09:34:14 	snort[32933]:
    Dec 10 09:34:14 	snort[32933]: --== Initialization Complete ==--
    Dec 10 09:34:14 	snort[32933]: --== Initialization Complete ==--
    Dec 10 09:34:14 	snort[32933]: Snort initialization completed successfully (pid=32933)
    Dec 10 09:34:14 	snort[32933]: Snort initialization completed successfully (pid=32933)
    Dec 10 09:34:14 	snort[32933]: Not Using PCAP_FRAMES
    Dec 10 09:34:14 	snort[32933]: Not Using PCAP_FRAMES
    
    

Log in to reply