samsamwun
December 6th, 2004, 09:15
Hi list,

I have setup Sguil in FreeBSD 5.3 stable. I got the following error when the server starting up:
PONG recieved
Unable to load PS data into DB.
ERROR 1146 at line 1: Table 'sguildb.sancp' doesn't exist
Unable to load PS data into DB.
ERROR 1146 at line 1: Table 'sguildb.sancp' doesn't exist
1864 Snort rules read...
1864 Option Chains linked into 187 Chain Headers
0 Dynamic rules

I read the previous post w.r.t this error, I have enable infile option when building mysql40.22 server. But the problem still persist.

The winxp version of sguil client also can't login sguil server. The error is:
e:\tcl\tlib\tls1.4 not found.

Where can I download tls1.4 for Windows?

Thanks
Sam

bsdjunkie
December 6th, 2004, 10:56
I am not sure if sancp is supported under a windows install of Sguil. You may want to email the sguil mailing list or pop on irc.freenode.net in #snort-gui and ask a developer. As to the TCL, you need Activestate TCL for Windows.
http://www.activestate.com/Products/ActiveTcl/

samsamwun
December 6th, 2004, 11:13
I am not sure if sancp is supported under a windows install of Sguil. You may want to email the sguil mailing list or pop on irc.freenode.net in #snort-gui and ask a developer. As to the TCL, you need Activestate TCL for Windows.
http://www.activestate.com/Products/ActiveTcl/

The problem appeared in Sguil server.
I have installed activeTcl and Tls1.5 in winxp, the Tls problem is fixed.
If I ignore the problem with Sancp, will I still have the Sguil running handle everything?

Thanks
Sam

bsdjunkie
December 6th, 2004, 12:59
sancp is a replacement for the snort stream4 keepstats. Richard Bejtlich has an install doc that explains everything quite well, and shows how to enable/disabler which one you choose to use. It is not necessary to use sancp with sguil.

http://sguil.sourceforge.net/index.php?page=latest_docs