Closed GoogleCodeExporter closed 8 years ago
There's your problem:
/var/log/snort/snort.log.1269509132: tcpdump capture file
You are logging in tcpdump format, and not unified format. Take a look at page
102 of
the snort manual.
Version 1.7 of SnoGE only supports unified1 format, try this in your snort.conf.
output alert_unified: snort.alert, limit 128
Let me know if it works.
Original comment by leon.j.w...@gmail.com
on 31 Mar 2010 at 11:34
Thanks
Seems working correctly now
************
Working on single file /var/log/snort/snort.log.1270038206
- In total 0 were make to the KML file
Original comment by tba...@gmail.com
on 31 Mar 2010 at 12:29
Original comment by leon.j.w...@gmail.com
on 31 Mar 2010 at 12:39
Original issue reported on code.google.com by
tba...@gmail.com
on 31 Mar 2010 at 11:27