There are a few basic steps to make Snort work with MySQL. A high level step-by-step approach to build a Snort-MySQL system follows. Details of each step will be presented later in the chapter.
Compile Snort with MySQL support and install it. Make sure that Snort is working properly by creating some alert messages. You have to use --withmysql command line argument with the configure script as mentioned in Chapter 2.
Install MySQL and use mysql client to make sure the database is available. See Appendix C for basic information about how to get started with MySQL.
Create a database on the MySQL server for Snort. I have named this database “snort.” You may choose any name for the database. This is explained ...