Snort mailing list archives

barnyard question?


From: Omolayo Salako <OSalako () corp goamerica net>
Date: Wed, 8 May 2002 13:52:13 -0400

i have got barnyard working, well so i thought. i am running it in deamon
mode and it reads an unified alert file created by snort, when the file is
not in my /var/log/snort directory barnyard exits with a no file to read
error. The readme file says you can run it in continous mode where it
continously run whether the file it's there or not, but it does not specify
how. How does snort read the conf file?, if it reads it sequentially, i
suppose you will have to comment out database option and uncomment logging
and alerting options. because if both are uncommented snort in snort.conf it
will log to both database and the alert file it creates, which we dont want.
in barnyard.conf it specifies database schema for acid. since the schema
pertains to the database and not the frontend, i believe this should work
for demarc also. my questions are how do i run barnyard in continous mode
w/o checkpoint so that it does not exist if there is no alert file and has
anyone done this before with acid or demarc?. Suggestions would be greatly
appreciated.

_______________________________________________________________

Have big pipes? SourceForge.net is looking for download mirrors. We supply
the hardware. You get the recognition. Email Us: bandwidth () sourceforge net
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: