Bluehost.com Web Hosting $6.95

[Snort-users] Barnyard seems to do nothing

This is a discussion on [Snort-users] Barnyard seems to do nothing within the Snort forums, part of the System Security and Security Related category; Hi. I've got Snort 2.0.2 installed and working fine on my network - although it's looking for ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 11-05-2003
Iain Hallam
 
Posts: n/a
Default [Snort-users] Barnyard seems to do nothing

Hi.

I've got Snort 2.0.2 installed and working fine on my network - although
it's looking for scans from $HOME_NET to catch local problems rather
than preventing external problems. I decided that I'd like to process
Snort's output more flexibly, so I compiled barnyard 0.1 and used "make
install" to get it set up.

The command line I'm using for barnyard is:

/usr/bin/barnyard -c /etc/snort/barnyard.conf -d /var/log/snort \
-g /etc/snort/rules/gen-msg.map -s /etc/snort/rules/sid-msg.map \
-f alert -D

From the USAGE file I take this to mean that barnyard will work in
continuous mode, but there never seems to be a barnyard process on the
system after this runs - I just get:

-*> Barnyard! <*-
Version 0.1.0 (Build 17)
By Andrew R. Baker (andrewb@snort.org)
and Martin Roesch (roesch@sourcefire.com, www.snort.org)

Can anyone tell me what steps I should take from here to try to find out
what's going on with barnyard, please?

Thanks,

Iain Hallam.

P.S.: Incidentally, my snort.conf has both alert_unified and log_unified
output plugins enabled, but only snort.log appears in unified format.



-------------------------------------------------------
This SF.net email is sponsored by: SF.net Giveback Program.
Does SourceForge.net help you be more productive? Does it
help you create better code? SHARE THE LOVE, and help us help
YOU! Click Here: http://sourceforge.net/donate/
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 08:19 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0