Re: [Snort-users] Quick Barnyard question...

This is a discussion on Re: [Snort-users] Quick Barnyard question... within the Snort forums, part of the System Security and Security Related category; --0__=0ABBFAC9DFE1B0FE8f9e8a93df938690918c0ABBFAC9DF E1B0FE Content-type: text/plain; charset=ISO-8859-1 Content-transfer-encoding: quoted-printable Oh. so sguil is ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 08-11-2005
Mihai Petre
 
Posts: n/a
Default Re: [Snort-users] Quick Barnyard question...

--0__=0ABBFAC9DFE1B0FE8f9e8a93df938690918c0ABBFAC9DF E1B0FE
Content-type: text/plain; charset=ISO-8859-1
Content-transfer-encoding: quoted-printable


Oh.
so sguil is only a mysql output for a dbase with a different schema tha=
n
the acid/base.
Right ?

Thanks for the clarification
Mishou

On 08/11/2005 04:46:13 PM Paul Schmehl wrote:
>--On Thursday, August 11, 2005 15:47:21 -0400 Mihai Petre
><MPetre@morneausobeco.com> wrote:
>>
>> two more questions
>>
>> * The sguil output is part of the normal build or the source has to =

be
>> patched ?

>
>The sguil plugin is built in to barnyard 0.2.0. You do not have to pa=

tch
>it.
>
>> * The output can be directed to different outputs in the same time ?=

I
>> mean using mysql and sguil together is it "doable" ?
>>

>If you're going to run sguil, you *must* run mysql. Sguil uses mysql =

for
>everything.
>
>Paul Schmehl (pauls@utdallas.edu)
>Adjunct Information Security Officer
>University of Texas at Dallas
>AVIEN Founding Member
>http://www.utdallas.edu/ir/security/


Le pr=E9sent courriel et toutes les pi=E8ces jointes contiennent de
l'information priv=E9e, exclusive, privil=E9gi=E9e et/ou confidentielle=

s'adressant uniquement au destinataire. Toute utilisation, copie ou
distribution non autoris=E9e du contenu de ce courriel est strictement
interdite. Si vous n'=EAtes pas le destinataire de ce message et que vo=
us
l'avez re=E7u par erreur, veuillez le supprimer et en informer imm=E9di=
atement
l'exp=E9diteur.

This e-mail communication, including all attachments, may contain priva=
te,
proprietary, privileged and/or confidential information and is intended=

only for the person to whom it is addressed. Any unauthorized use, copy=
ing
or distribution of the contents of this e-mail is strictly prohibited. =
If
you are not the intended recipient of this e-mail, and have received it=
in
error, please delete it and notify the sender immediately.=

--0__=0ABBFAC9DFE1B0FE8f9e8a93df938690918c0ABBFAC9DF E1B0FE
Content-type: text/html; charset=ISO-8859-1
Content-Disposition: inline
Content-transfer-encoding: quoted-printable

<html><body>
<p>Oh.<br>
so sguil is only a mysql output for a dbase with a different schema tha=
n the acid/base.<br>
Right ?<br>
<br>
Thanks for the clarification<br>
Mishou<br>
<br>
On 08/11/2005 04:46:13 PM Paul Schmehl wrote:<br>
&gt;--On Thursday, August 11, 2005 15:47:21 -0400 Mihai Petre<br>
&gt;&lt;MPetre@morneausobeco.com&gt; wrote:<br>
&gt;&gt;<br>
&gt;&gt; two more questions<br>
&gt;&gt;<br>
&gt;&gt; * The sguil output is part of the normal build or the source h=
as to be<br>
&gt;&gt; patched ?<br>
&gt;<br>
&gt;The sguil plugin is built in to barnyard 0.2.0. You do not have to=
patch<br>
&gt;it.<br>
&gt;<br>
&gt;&gt; * The output can be directed to different outputs in the same =
time ? I<br>
&gt;&gt; mean using mysql and sguil together is it &quot;doable&quot; ?=
<br>
&gt;&gt;<br>
&gt;If you're going to run sguil, you *must* run mysql. Sguil uses mys=
ql for<br>
&gt;everything.<br>
&gt;<br>
&gt;Paul Schmehl (pauls@utdallas.edu)<br>
&gt;Adjunct Information Security Officer<br>
&gt;University of Texas at Dallas<br>
&gt;AVIEN Founding Member<br>
&gt;<a href=3D"http://www.utdallas.edu/ir/security/">http://www.utdalla=
s.edu/ir/security/</a><br>
<br>
<i><font size=3D"2" color=3D"#808080">Le pr=E9sent courriel et toutes l=
es pi=E8ces jointes contiennent de l'information priv=E9e, exclusive, p=
rivil=E9gi=E9e et/ou confidentielle s'adressant uniquement au destinata=
ire. Toute utilisation, copie ou distribution non autoris=E9e du conten=
u de ce courriel est strictement interdite. Si vous n'=EAtes pas le des=
tinataire de ce message et que vous l'avez re=E7u par erreur, veuillez =
le supprimer et en informer imm=E9diatement l'exp=E9diteur.</font></i><=
br>
<br>
<i><font size=3D"2" color=3D"#808080">This e-mail communication, includ=
ing all attachments, may contain private, proprietary, privileged and/o=
r confidential information and is intended only for the person to whom =
it is addressed. Any unauthorized use, copying or distribution of the c=
ontents of this e-mail is strictly prohibited. If you are not the inten=
ded recipient of this e-mail, and have received it in error, please del=
ete it and notify the sender immediately.</font></i></body></html>=

--0__=0ABBFAC9DFE1B0FE8f9e8a93df938690918c0ABBFAC9DF E1B0FE--



-------------------------------------------------------
SF.Net email is Sponsored by the Better Software Conference & EXPO
September 19-22, 2005 * San Francisco, CA * Development Lifecycle Practices
Agile & Plan-Driven Development * Managing Projects & Teams * Testing & QA
Security * Process Improvement & Measurement * http://www.sqe.com/bsce5sf
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 04:00 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0