Snort mailing list archives

Re: Barnyard Acid MySQL problem


From: Robert Vance Jr <rev () northwestern edu>
Date: Thu, 06 Nov 2003 11:41:15 -0600

When sending output to Acid/Mysql using only snort, my signature field
would list something like this below...

SCAN Proxy (8080) attempt

After setting up Barnyard I am now getting this...

Snort Alert [1:618:0] 

My first guess would be that when you fired up your barnyard process,
you did not configure it to use the sid-msg.map file.  This file maps
signature ids to their respective alert message.  So try something like
this...

/path/to/barnyard -s /path/to/sid-msg.map

You'll want to include any other command line parameters that you're
already using as well.

rev
--


-------------------------------------------------------
This SF.net email is sponsored by: SF.net Giveback Program.
Does SourceForge.net help you be more productive?  Does it
help you create better code?   SHARE THE LOVE, and help us help
YOU!  Click Here: http://sourceforge.net/donate/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: