[Sguil-users] Alerts not displaying in squil client
Status: Beta
Brought to you by:
bamm
From: Al C. <ima...@gm...> - 2010-10-08 17:00:19
|
I have installed squil/snort using the Redhat How-To on a CentOS 5.5 box. I have the sensor and the server on the same box. Everything installed fine and all the services are running. However no alerts are displaying in the squil client. It appears that alerts are in the database, although I don't know how to query the database directly to confirm this (I am seeing the time stamps change on many of the database files). I am getting PADS data displaying in the client. The only other symptom is in the Agent Status window, the only field that is not showing a timestamp in the Last column is snort, although I do have a green up status in the Status field. Any thought on why my alerts are not displaying in the client? Thanks in advance for your help, Al |