我在做snort+base的实验。用barnyard2 -c /etc/snort/barnyard2.conf -d /var/log/snort/ -f snort.log –w /var/log/snort/barnyard2.waldo后,给我的报错是:
Waiting for new data 07/01-00:30:48.562104 [] [1:1000003:1] Snort Alert [1:1000003:0] [] [Classification ID: (null)] [Priority ID: 0] {ICMP} 192.168.209.1 -> 192.168.209.140 database: mysql_error: Field 'sig_class_id' doesn't have a default value SQL=INSERT INTO signature (sig_name,sig_rev,sig_sid,sig_gid) VALUES ('Snort Alert [1:1000003:0]',1,1000003,1)
database: Problem inserting a new signature 'Snort Alert [1:1000003:0]': INSERT INTO signature (sig_name,sig_rev,sig_sid,sig_gid) VALUES ('Snort Alert [1:1000003:0]',1,1000003,1)
报警信息能在数据库里查到,但是base主页的柱状图里都是0
自定义的rule是alert icmp any any -> $HOME_NET any (msg:"ICMP Packet Detected";sid:1000003;rev:1;)
如果您能帮帮忙,不胜感激【哭死/(ㄒoㄒ)/~~】


