Thank you, it makes more sence now as to what those files are. I stoped useing snortsnarf and am now useing WinSnort2HTML for analizeing my logs, I looked into ACID but I dont have any database for it.
I have determines why alert.ids was empty. After a few months of thinking snort was working, and haveing a empty alert.ids got me thinking. But since I used IDScenter and there were no errors in the overview section of IDScenter, I was led to believe snort was running quietly in the background. I noticed a button for test configuration, so I stoped snort, and tested my configuration, which then informed me there was a fata error, I had an invalid argument to one of the preprocessors, which I then dicovered was I had typed the argument list in the wrong format. I fix this and saved the configuraton. And now snort is loging to alert.ids




Reply With Quote