Enter the 'Login name' and 'Password',
remember the first time u use SnortCenter the Login name is 'admin' and the password is 'change'
Time to add a Sensor Agent....
Click on 'Sensor Console' -> 'Add Sensor'
Fill-in all the fields (Snort command line, is optional. SnortCenter will create a command line for you)
The interface should be the interface that snort has to sniff on (etc: eth0)
Click on the 'Save' button
The Sensor Console screen should now look like this.
If the sensor doesn't has an 'orange' color, but is 'red' then see in the 'sensor message' field what's wrong.
Maybe you entered a wrong username, password, sensor agent port, ...
You can edit the sensor settings by clicking on the
'edit' icon in front of the sensor and then click on update.
Click on 'Admin' -> 'Import / Update Rules' -> 'Update from Internet'
When you see the 'Update Report' all the variables, proprocessor, rules, ... will be imported into the Database.
SnortCenter has also automatic activated all the rules, variables, preprocessors, ... that are enabled in the original snort.conf file.
Click on the 'Sensor Console'
button
Now click on 'Push' to send the snort configuration file to the sensor.
When the screen is loaded again click on 'Start'
Now the sensor should look green with the text 'Snort is running Pid# xxx'
That's all to get a sensor up and running, ofcourse you want to change somethings like etc. DB output plugin, $HOME_NET, Rules...
For more information about managing sensors, read the other chapters in this manual!
Not yet written !!!!!!