Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Snort.org Discussion » snort IDMEF-xml problems

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

snort IDMEF-xml problems


Posted by sebastian on March 23, 2006 22:29:14

dear all:

It's the error message...

[img]http://www.oz.stu.edu.tw/s91113259/www/screenshot.jpg[/img]


snort.conf :

output idmef: $HOME_NET facility_default=file|/var/log/snort/idmef_alerts.log \
dtd=/usr/share/doc/snort-2.3.2/idmef-message.dtd analyzerid=IDS1 \
output=alert name=biff default=ascii indent=true

We can't find the problem.
Have somebody can help us?

about the snort's version:
fedora core 3
snort 2.3.2
use mysql
libidmef-1.0.2-alpha.tar.gz
libxml-1.8.17.tar.gz
snort-idmef-plugin-2.0.0alpha.tar.gz