I’m trying to get Aanval to display events from Snort and I believe I am almost there. Aanval sees the Sensor and things seem to work (see screenshots).
It can display events from the Aanval console and both sensors are active. I have 2 active sensors one from Aanval and one from Snort. I know the trial license only supports one sensor but even when I turn off the Aanval sensor I can’t see the events from Snort.
Barnyard is writing events in the db:
The interesting thing is probably the error.log which is full with lines like this:
Mar 13 09:01:09 [ERROR] [10.50.5.12] [root : 1] MySQL Query Error: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ') ORDER BY mas.id DESC LIMIT 10' at line 1
Mar 13 09:01:09 [ERROR] [10.50.5.12] [root : 1] MySQL Query Error: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ') GROUP BY created ORDER BY created' at line 1
Mar 13 09:01:09 [ERROR] [10.50.5.12] [root : 1] MySQL Query Error: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ')' at line 1
Mar 13 09:01:09 [ERROR] [10.50.5.12] [root : 1] MySQL Query Error: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ') AND timestamp >= 1363164669' at line 1
Mar 13 09:01:09 [ERROR] [10.50.5.12] [root : 1] MySQL Query Error: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ') AND timestamp >= 1363161669' at line 1
Mar 13 09:01:09 [ERROR] [10.50.5.12] [root : 1] MySQL Query Error: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ') AND timestamp >= 1363132800' at line 1
Mar 13 09:01:09 [ERROR] [10.50.5.12] [root : 1] MySQL Query Error: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ') ORDER BY mas.id DESC LIMIT 15' at line 1
Mar 13 09:06:09 [ERROR] [10.50.5.12] [root : 1] MySQL Query Error: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ') ORDER BY mas.id DESC LIMIT 10' at line 1
Mar 13 09:06:09 [ERROR] [10.50.5.12] [root : 1] MySQL Query Error: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ') GROUP BY created ORDER BY created' at line 1
Mar 13 09:06:09 [ERROR] [10.50.5.12] [root : 1] MySQL Query Error: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ')' at line 1
Mar 13 09:06:09 [ERROR] [10.50.5.12] [root : 1] MySQL Query Error: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ') AND timestamp >= 1363164969' at line 1
To test the SQL statements I run some select statements form the debug.log directly in mysql and they run just fine without a problem. I tried those that invoke the timestamp command as the timestamp seems to be a problem according to the error.log.
Can it be a versioning issue? I'm running Aanval SAS v7.1 (70142) and MySQL Ver 14.14 Dist 5.5.30 x86_64.
Any help is greatly appreciated!
--
You received this message because you are subscribed to the Google Groups "Aanval - Snort & Syslog SIEM (Correlation and Threat Management)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to aanval+un...@googlegroups.com.
To post to this group, send email to aan...@googlegroups.com.
Visit this group at http://groups.google.com/group/aanval?hl=en.
For more options, visit https://groups.google.com/groups/opt_out.