Re: Is snort-stat and 5snort really broken in sid?

2001-09-12 Thread James Nord
[EMAIL PROTECTED] wrote: What version are you using?? make sure the following line is in your snort.conf -- I think the debian equiv is snort-lib: output alert_syslog: LOG_AUTH --sjk On 12 Sep, Andrew Pollock wrote: Even if I run snort-stat manually on auth.log (after I've made snort start

Re: Is snort-stat and 5snort really broken in sid?

2001-09-12 Thread Andrew Pollock
On 12.09.2001 at 11:30:02, Andrew Pollock [EMAIL PROTECTED] wrote: Even if I run snort-stat manually on auth.log (after I've made snort start with -s) it doesn't return anything when there are alerts in the log. Any suggestions appreciated, I'd like to get daily summary emails. Well I

Re: Is snort-stat and 5snort really broken in sid?

2001-09-12 Thread James Nord
[EMAIL PROTECTED] wrote: What version are you using?? make sure the following line is in your snort.conf -- I think the debian equiv is snort-lib: output alert_syslog: LOG_AUTH --sjk On 12 Sep, Andrew Pollock wrote: Even if I run snort-stat manually on auth.log (after I've made snort start

Re: Is snort-stat and 5snort really broken in sid?

2001-09-12 Thread Andrew Pollock
On 12.09.2001 at 11:30:02, Andrew Pollock [EMAIL PROTECTED] wrote: Even if I run snort-stat manually on auth.log (after I've made snort start with -s) it doesn't return anything when there are alerts in the log. Any suggestions appreciated, I'd like to get daily summary emails. Well I

Is snort-stat and 5snort really broken in sid?

2001-09-11 Thread Andrew Pollock
Hi, I've always had problems with 5snort killing snort daily when snort's running in dialup mode (I fixed that by commenting out the restart line) but I'm not getting anything in the daily notification emails either. /etc/ppp/ip-up.d/snort doesn't start snort with -s, so nothing goes into

Re: Is snort-stat and 5snort really broken in sid?

2001-09-11 Thread sjk
What version are you using?? make sure the following line is in your snort.conf -- I think the debian equiv is snort-lib: output alert_syslog: LOG_AUTH --sjk On 12 Sep, Andrew Pollock wrote: Hi, I've always had problems with 5snort killing snort daily when snort's running in dialup mode

Is snort-stat and 5snort really broken in sid?

2001-09-11 Thread Andrew Pollock
Hi, I've always had problems with 5snort killing snort daily when snort's running in dialup mode (I fixed that by commenting out the restart line) but I'm not getting anything in the daily notification emails either. /etc/ppp/ip-up.d/snort doesn't start snort with -s, so nothing goes into

Re: Is snort-stat and 5snort really broken in sid?

2001-09-11 Thread sjk
What version are you using?? make sure the following line is in your snort.conf -- I think the debian equiv is snort-lib: output alert_syslog: LOG_AUTH --sjk On 12 Sep, Andrew Pollock wrote: Hi, I've always had problems with 5snort killing snort daily when snort's running in dialup mode

Re: Is snort-stat and 5snort really broken in sid?

2001-09-11 Thread Andrew Pollock
On 12.09.2001 at 12:24:59, [EMAIL PROTECTED] wrote: What version are you using?? Version 1.8-RELEASE (Build 43) make sure the following line is in your snort.conf -- I think the debian equiv is snort-lib: output alert_syslog: LOG_AUTH I've uncommented this line in my snort.conf. I'm