Hello Team,
My Aanval console doesn't show new Snort events. This is a better description of the environment:
- Red Hat 5.3 with MySQL server, Aanval DB, Snort DB and Barnyard2;
- Aanval "aanval-7-latest-stable.tar". BPU Version: 7.0.700;
- snort-2.9.5.5;
- barnyard2-1.9;
- Snort sensor on eth0 10.X.X.X. Events are logged in /var/log/snort and listed:
1 snort snort 0 Jan 3 10:52 snort.log
1 snort snort 5258 Dec 28 12:31 snort.log.1388229379
1 snort snort 6304 Dec 29 18:18 snort.log.1388235421
1 snort snort 0 Jan 12 15:15 snort.log.1388343157
1 snort snort 4794 Jan 3 00:56 snort.log.1388672358
1 snort snort 0 Jan 3 15:35 snort.log.1388763342
1 snort snort 8668 Jan 10 00:27 snort.log.1388765130
Aanval configuration:
Configuration/Device Management ---> device Snort IP Address ETH0 10.X.X.X
Snort Settings ---------> The Snort Database in the localhost
Sensor Configuration ---------> SMT
12345678901 Last Event
12-29-2013 18:18:10 (NOTE. Last event exactly matches the snort.log.1388235421) User Permission is ON.
Snort Management ----------->
| Last SMT Status Check
|
01-01-1970 00:00:00 (1389561075 seconds ago)
|
|
Last SMT Heartbeat
|
01-01-1970 00:00:00 (1389561075 seconds ago)
|
|
SMT Heartbeat Count
|
0 |
The sensor status check doesn't return anything.
The problem is that Aanval doesn't seem to have control of the sensor during the Sensor Management and therefore it doesn't show events stored in the recent snort.log.XXXXX
Do you have an idea what the problem might be?
Thanks.
Regards
Sal