Re: Prewikka not reporting agents or events

Jason Dixon <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.user
Message-ID <[email protected]>
On Thu, Nov 20, 2008 at 10:01:32AM +0530, rinku buragohain wrote:
> 
> On Thu, Nov 20, 2008 at 3:20 AM, Jason Dixon <[email protected]> wrote:
> 
> > I'm having some difficulty with Prewikka not showing any events or
> > agents.  I built libprelude, libpreludedb, prelude-lml, and
> > prelude-manager from source on our CentOS 5.2 snort server.  I also
> > rebuilt snort with --enable-prelude from the official Snort spec
> > file.  Prewikka works fine, as does snort (logging to file).  I used
> > prelude-admin to register a "snort" profile and enabled this profile in
> > snort.conf.  I don't see where snort is attempting to connect to
> > prelude-manager, but I don't see any errors either.  Any suggestions?
> >
> > P.S.  I noticed that nowhere in the User Manual does it mention starting
> > the prelude-manager.  I think it assumes that most users will install
> > from binary package (although the installation documentation is
> > otherwise excellent).  Is this an oversight by the author, or do I not
> > need to start prelude-manager manually?
> 
> as per my knowlege prelude manager will be your server and the sensor will
> be your client.. so to register your sensor to server you have to first run
> the prelude-manager then start the sensor(snort)..just try it

I must not have communicated very well in my initial post.  I've already
started up prelude-manager and have registered the sensor.  I configured
snort.conf to use the prelude output and started up snort.  It reports
nothing about connecting (or attempting to connect) to prelude.

Thanks,

-- 
Jason Dixon
OmniTI Computer Consulting, Inc.
[email protected]
443.325.1357 x.241
_______________________________________________
Prelude-user site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-user
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.