Snort mailing list archives
Issue with barnyard & unified alert log file
From: Marc Dreher <MarcDreher () gmx net>
Date: Fri, 6 Sep 2002 13:46:17 +0200 (MEST)
Sorry, forgot subject in last post ... Hi all, I posted this question already a couple of days ago. As I did not get an answer either nobody knows (which I doubt) or it is a very well known issue and I was tu stupid to find the answer in the faq or list history (although I looked closly). The problem is the following. When I have snort logging alerts in unified form to a file and take this file as input for barnyard to write the output either to syslog or the alert_fast output plugin I do not get any IP adresses or time information for spp_portscan alerts. Output from alert_fast for example looks like this: 01/01/-30-00:00:00.000000 {IP} 0.0.0.0 -> 0.0.0.0 [**] [100:2:1] spp_portscan: Portscan Status [**] [Classification: Not Suspicious Traffic] [Priority: 0] all other alerts are fine. When I have snort log into the plain ascii alert file everything is ok as well. Thanks fo any hints. Regards Marc -- GMX - Die Kommunikationsplattform im Internet. http://www.gmx.net ------------------------------------------------------- This sf.net email is sponsored by: OSDN - Tired of that same old cell phone? Get a new here for FREE! https://www.inphonic.com/r.asp?r=sourceforge1&refcode1=vs3390 _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- (no subject), (continued)
- (no subject) kohat enclave (Aug 21)
- Re: (no subject) Piotr Pietrowski (Aug 22)
- Re: (no subject) John Sage (Aug 22)
- (no subject) Alvaro Lillo (Aug 25)
- Just one match could cover serious attack Alvaro Lillo (Aug 25)
- Re: Just one match could cover serious attack John Sage (Aug 25)
- Just one match could cover serious attack Alvaro Lillo (Aug 25)
- (no subject) S.M.Karthik (Aug 26)
- (no subject) Lionel Fairon (Aug 28)
- Re: (no subject) Roman Danyliw (Sep 05)
- (no subject) Marc Dreher (Sep 06)
- Issue with barnyard & unified alert log file Marc Dreher (Sep 06)
- (no subject) Earl D. Fife (Sep 11)
- (no subject) Sergg B. (Sep 15)
- (no subject) snort bsd (Sep 22)
- (no subject) Roger Parx (Sep 24)
- RE: (no subject) Wayne T Work (Sep 24)
- Re: (no subject) Joe Giles (Sep 24)
- (no subject) Lakshmi (Sep 25)
- (no subject) 赵光明 (Sep 28)
- (no subject) kohat enclave (Aug 21)