Snort mailing list archives
Re: Barnyard's explained
From: Jason Haar <Jason.Haar () trimble co nz>
Date: Wed, 21 Jul 2004 21:35:45 +1200
On Tue, Jul 20, 2004 at 07:33:22PM -0700, Tom Fulton wrote:
Can someone explain what the benefit is of using Barnyard? I understand that the unified output plug in allows Snort to write alerts and logs into a single binary file which frees up processing from the detection engine (as apposed to writing to a flat file, etc) so that Snort runs faster overall. However, Snort does that by itself. I'm not clear on what value Barnyard adds to this.
What do you mean by "Snort does that by itself" then? Barnyard needs to be compared with getting Snort to output directly into a SQL backend. The latter means Snort is constrained (blocked) when the alerts are generating more data than the backend SQL database can handle. With barnyard, snort "just dumps" the data straight to disk (much faster than pushing into a SQL DB), and barnyard post-processes it into SQL out-of-band. Obviously it would be best to have Snort dump to disk (unified format), and to rsync that data at (say) ten-minute intervals to a SEPARATE box, which has barnyard to dump the data into a SQL DB. That way there's nothing by I/O and network traffic involved in generating the data - all the CPU is available for "pure" sniffing. -- Cheers Jason Haar Information Security Manager, Trimble Navigation Ltd. Phone: +64 3 9635 377 Fax: +64 3 9635 417 PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1 ------------------------------------------------------- This SF.Net email is sponsored by BEA Weblogic Workshop FREE Java Enterprise J2EE developer tools! Get your free copy of BEA WebLogic Workshop 8.1 today. http://ads.osdn.com/?ad_id=4721&alloc_id=10040&op=click _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Barnyard's explained Tom Fulton (Jul 20)
- Re: Barnyard's explained sekure (Jul 20)
- Re: Barnyard's explained Jason Haar (Jul 21)
- Re: Barnyard's explained Dirk Geschke (Jul 21)
- Re: Barnyard's explained Alejandro Flores (Jul 21)