Snort mailing list archives
Re: Barnyard Acid MySQL problem
From: Robert Vance Jr <rev () northwestern edu>
Date: Thu, 06 Nov 2003 11:41:15 -0600
When sending output to Acid/Mysql using only snort, my signature field would list something like this below... SCAN Proxy (8080) attempt After setting up Barnyard I am now getting this... Snort Alert [1:618:0]
My first guess would be that when you fired up your barnyard process, you did not configure it to use the sid-msg.map file. This file maps signature ids to their respective alert message. So try something like this... /path/to/barnyard -s /path/to/sid-msg.map You'll want to include any other command line parameters that you're already using as well. rev -- ------------------------------------------------------- This SF.net email is sponsored by: SF.net Giveback Program. Does SourceForge.net help you be more productive? Does it help you create better code? SHARE THE LOVE, and help us help YOU! Click Here: http://sourceforge.net/donate/ _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Barnyard Acid MySQL problem Billy Wright (Nov 06)
- Re: Barnyard Acid MySQL problem Robert Vance Jr (Nov 06)
- <Possible follow-ups>
- RE: Barnyard Acid MySQL problem SRH-Lists (Nov 06)