https://blog.snort.org/2012/07/database-output-is-dead-rip.html
For those of you that originally compiled Snort like: ./configure --enable-mysql
Or, if you look in your snort.conf and your "output" lines look like this:
output database: alert
Our recommendation is that after you upgrade to Snort 2.9.3.0, you move to full unified2 logging and use barnyard2 to read those unified2 files and input them into your mysql database.
好像這個plugin被移掉了,用barnyard2代替,你先看看你網路說明的版本吧。