Snort mailing list archives

Re: multiple instances of snort and barnyard


From: Joel Esler <joel.esler () sourcefire com>
Date: Wed, 23 Aug 2006 12:05:04 -0400

You can create different directories for each instance, Have all the unified filed for each instance of Snort log to 
its own directory, then have 3 instances of barnyard, each reading from it's respective directory.

Joel


On Wed, Aug 23, 2006 at 09:41:05AM -0500, Spencer Anderson apparently sent me:
I run several instances of Snort on SuSE Linux (to monitor traffic on
2-3 NICs) and I have been logging directly to a MySQL database. I would
like to start using the unified output and barnyard.  I have it working
for the most part, the problem is I have a unified output file for each
interface that I have snort listening on and I can't get multiple
instances of barnyard to run in continuous mode to process each log
file. 

I'd prefer to run barnyard in batch mode in 10 minute intervals on each
log file, I can't seem to do that either without restarting snort each
time after I run barnyard to create a new unified log file. 

Is there a way to run barnyard in batch mode so that each time it's run
against a file it only processes events that it hasn't processed before?


Or, is there a way to have multiple continuous instances of barnyard
running so each instance can maintain its corresponding snort unified
log file? 

Or, is there a better way to have each event captured by snort
associated with the network interface it was detected on? 

SuSE Enterprise 9 
Snort 2.4.5 
Barnyard 0.2.0 

Thanks, 
Spencer 

-------------------------------------------------------------------------
Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

+---------------------------------------------------------------------+
joel esler          senior security consultant         1-706-627-2101
Sourcefire    Security for the /Real/ World -- http://www.sourcefire.com
       Snort - Open Source Network IPS/IDS -- http://www.snort.org
         gpg key: http://demo.sourcefire.com/jesler.pgp.key
           aim:eslerjoel  ymsg:eslerjoel gtalk:eslerj
+---------------------------------------------------------------------+

-------------------------------------------------------------------------
Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: