Why MySQL?
MySQL is a free database that works on a number of platforms, including Windows which allows Snort to log directly to MySQL natively, as the alerts come in.
While MySQL is not required with Snort, it is required for a front-end console such as ACID. If you set up MySQL or another database system, you can see the alerts without the front-end console, but you really do not need that kind of pain.
Installing MySQL 5.0.18
Download MySQL version 5.0.18 from
http://www.mysql.com/Downloads/index.html/.
Uncompress the MySQL.ZIP file into a temporary directory. This file is ZIP file.You need a compression utility (such as WinZip or WinRAR) to uncompress it on a Windows 2000 platform.
Where you uncompressed the file, double-click setup.exe. The Welcome window (Fig. 4.1.11) appears.
Fig. 4.1.11 Welcome Window for MySQL
Click Next, The Information window (Fig. 4.1.12) appears. Choose custom installation and click Next.
Fig. 4.1.12 Information Window for MySQL
Click Change to change the default installation directory of MySQL (Fig.4.1.13).
Fig. 4.1.13 Custom Setup Window
In the folder name field type “c:\mysql” (Fig. 4.1.14) and press OK button to go back to the custom setup window.
Fig. 4.1.14 Installation Location
Click next twice to proceed with the installation.
When installation finishes, it will prompt you to sign-up. Skip it right now.
MySQL will prompt you to configure MySQL now (Fig.4.1.15). Click Next.
Fig. 4.1.15 MySQL Configuration Welcome Window
Click next, In MySQL server instance configuration window (Fig.4.1.16) select standard configuration then click next
Fig. 4.1.16 MySQL Configuration
Make sure “Install As Windows Service” is selected (Fig. 4.1.16), Service name MySQL and include Bin Directory is also selected then press next.
Fig. 4.1.16 MySQL Server Instance
Type a new root password and confirm it, which is shown as Fig. 4.1.17.
Fig. 4.1.17 MySQL Password Window
Click execute button and you are all done.
Why IDScenter?
Snort only provides command line operation, which makes it tough for most users to use, for example, we have to memorize and type in the long command name each time, limited information display, etc. IDScenter can provide a friendly graphical interface for Snort. With the help of IDScenter, it is much easier to run Snort correctly.
Downloading & Installing IDScenter
Download IDScenter.zip (1.1 RC4, 04.08.2003) from
http://www.engagesecurity.com/downloads/#idscenter.
Unzip the download file to obtain the setup.exe.
Duple click on the setup.exe file to start the installation.
On the welcoming screen click next to start the installation.
Click yes to accept IDScenter program license.
Click next to accept the IDScenter default installation folder (“C:\Program Files\IDScenter” (Fig. 4.1.18).
Fig. 4.1.18 IDScenter Installation Folder
Click next twice to accept the default start menu folder and desktop icon (Fig. 4.1.19).
Fig. 4.1.19 Create Icon
Click install button.
After finishing the installation you should notice a black icon next to time field on the windows status bar. That means your software has been installed correctly.
Share with your friends: |