Quick Configuration Guide

Login Screen


Enter the 'Login name' and 'Password',
remember the first time u use SnortCenter the Login name is 'admin' and the password is 'change'
Time to add a Sensor Agent....

Add a Sensor Agent to the management console



Click on 'Sensor Console' -> 'Add Sensor'


Fill-in all the fields (Snort command line, is optional. SnortCenter will create a command line for you) The interface should be the interface that snort has to sniff on (etc: eth0)
Click on the 'Save' button



The Sensor Console screen should now look like this. If the sensor doesn't has an 'orange' color, but is 'red' then see in the 'sensor message' field what's wrong.


Maybe you entered a wrong username, password, sensor agent port, ...
You can edit the sensor settings by clicking on the 'edit' icon in front of the sensor and then click on update.

Importing the snort signatures from the internet



Click on 'Admin' -> 'Import / Update Rules' -> 'Update from Internet'


When you see the 'Update Report' all the variables, proprocessor, rules, ... will be imported into the Database.
SnortCenter has also automatic activated all the rules, variables, preprocessors, ... that are enabled in the original snort.conf file.

Pushing the configuration to the sensor and startup snort


Click on the 'Sensor Console' button


Now click on 'Push' to send the snort configuration file to the sensor.
When the screen is loaded again click on 'Start'



Now the sensor should look green with the text 'Snort is running Pid# xxx'

That's all to get a sensor up and running, ofcourse you want to change somethings like etc. DB output plugin, $HOME_NET, Rules...
For more information about managing sensors, read the other chapters in this manual!
Not yet written !!!!!!