Why are the sensors names being listed as unknown?
Snort sets this sensor name the first time it is started based in the IP address of the host. If the IP address cannot be resolved, the sensor name might be logged as ‘unknown’. Use the ‘sensor_name’ configuration option of the database output plugin to explicitly set the name of the sensor. For example, output database: log, mysql, sensor_name=foobar database=snort ….