tarballed
May 25th, 2003, 16:20
Ok. I just put up OpenBSD 3.3 with the new PF and I Like it!
Now, I am going to put on snort so I can do some more fun stuff.
I have a couple of questions though.
I know that elmore has put up a great How-To, however I wanted to ask a few questions about what is needed and rules and such.
First, is it recommended or required to have a database installed on the server to hold the log files? Since I have pretty much stripped my OpenBSD install to run as little processes as possible, what is the general rule if I need to setup a database for my snort logs? Should I install it on the firewall, or another server on my intranet?
Second. I see that snort 2.0 is out. But, I see there are two different rule sets that you can download; current and stable. Im guessing that the current rules go with 2.0?
Thanks everyone. Looking forward to putting up my hog!
Tarballed
Now, I am going to put on snort so I can do some more fun stuff.
I have a couple of questions though.
I know that elmore has put up a great How-To, however I wanted to ask a few questions about what is needed and rules and such.
First, is it recommended or required to have a database installed on the server to hold the log files? Since I have pretty much stripped my OpenBSD install to run as little processes as possible, what is the general rule if I need to setup a database for my snort logs? Should I install it on the firewall, or another server on my intranet?
Second. I see that snort 2.0 is out. But, I see there are two different rule sets that you can download; current and stable. Im guessing that the current rules go with 2.0?
Thanks everyone. Looking forward to putting up my hog!
Tarballed