[Sguil-users] 0.9.0 upgrade died
Status: Beta
Brought to you by:
bamm
From: James L. <jl...@sl...> - 2014-07-02 14:02:33
|
Topic says it...I'm unable to restart squild at this point in time: Starting with: sudo /opt/bin/sguil/sguild -c /opt/etc/snort/sguild/sguild.conf -C /opt/etc/snort/sguild/certs -a /opt/etc/snort/sguild/autocat.conf -g /opt/etc/snort/sguild/sguild.queries -A /opt/etc/snort/sguild/sguild.access mysqlexec/db server: Table 'sguildb.event_External_20140702' doesn't exist while executing "mysqlexec $MAIN_DB_SOCKETID $updateString" (procedure "UpdateDBStatus" line 11) invoked from within "UpdateDBStatus [lindex $data 3] [lindex $data 4] [lindex $data 5] [lindex $data 6] [GetCurrentTimeStamp] $AUTOID $acCat($rid)" (procedure "AutoCat" line 43) invoked from within "AutoCat $row" ("foreach" body line 6) invoked from within "foreach row [mysqlsel $MAIN_DB_SOCKETID $tmpQry -list] { InfoMessage "Archived Alert: $row" set LAST_EVENT_ID([lindex $row 3]) "[li..." invoked from within "if { $mergeTableListArray(event) != "" } { # Get the archived alerts LogMessage "Querying DB for archived events..." set MAJOR_MYSQL_VERS..." (file "/opt/bin/sguil/sguild" line 734) I have no clue on how to proceed beside blowing out the current database, which I really don't want to have to do... please help. Thank you. James |