•The rule file you are using should be mentioned in snort.conf file. A sample rule file under rules directory is already added and commented in snort.conf.
•Log files are stored in the installation
•When adding new rules to the file sample.rules, uncomment the line, “include sample.rules”in the file snort.conf.
•Snort rule syntax is different from
•The SID rule option is mandatory for Snort rules.
•Do not specify channel information in Snort rules as it is already specified in
Running the Sguil Server
Scripts are used to perform management tasks such as starting and stopping the server and adding and deleting users. Run scripts from the bin
Task | Script |
|
|
Start the server. When the Sguild server is started | ./StartMysqlserver.sh |
for the first time, you are prompted to add a new | ./Startserver.sh |
user. |
|
|
|
Stop the server. | ./Shutdownserver.sh |
| ./ShutdownMysqlserver.sh |
|
|
Add a new user. You are prompted for a new | ./ManageSguilserverUser.sh add |
username and password. |
|
|
|
Delete a user. You are prompted for your | ./ManageSguilserverUser.sh delete |
username and Squil user to be deleted. |
|
|
|
48 | Network Security Monitoring |