Re: [sentinix-list] Snort Conf.

Michel Blomgren <[email protected]> Fri, 26 Mar 2004 01:53:17 +0100
Newsgroups gmane.linux.sentinix
Message-ID <[email protected]>
On Friday 26 March 2004 00:09, RichardKebo-JdlnA/[email protected] wrote:
> OK. How do I edit the conf file that is stored in the MySQL database?

With SnortCenter, of course!

>
> On Wednesday 24 March 2004 18:24, RichardKebo-JdlnA/[email protected] wrote:
> > Hello,
> > I am trying to edit the snort.conf file. But I am not sure what file to
> > edit.
> > I edited /etc/snort/snort.conf but when I look at the snort
>
> configuration
>
> > file from within the sensor console of snortcenter it does not show the
> > change.
> > If I look at the system status on the console, it reports the conf file
> > being used is: /usr/local/snort/sensor/rules/snort.eth1.conf.
> > After I edit this file and reload, the changes still do not show up.
>
> SnortCenter uses a MySQL database, when you do a reload, SnortCenter takes
> the
> rule configuration it has stored in the MySQL database and writes the new
> snort.<if>.conf file. Either choose to use SnortCenter, if you want to
> edit
> snort.conf by hand, do not use SnortCenter at all.
>
> > Also, what distro is Sentinix based on? And how do we do updates?
>
> It's made from scratch, inspired by LFS and Slackware. Slackware packages
> *can
> not* be used with SENTINIX. The current version does not include package
> management, so you will have to download tarball sources, compile and
> install
> "manually".
>
>                  Michel
> _______________________________________________
> SENTINIX mailing list
> [email protected]
> http://elevenprospect.com/mailman/listinfo/sentinix