Snort mailing list archives

Barnyard and Drop events


From: Josep Román <josep.roman () gmail com>
Date: Wed, 3 Oct 2007 10:09:58 +0200

Hi all,

I guess some of you have already found the same problem as I have.

Having snort_inline & barnyard running, I found out the drop events are
being logged by snort_inline but not to being picked up by barnyard.
Therefore, they're not shown in the Base console.

Since I'm using only alert_unified & log_unified it took me a while until I
turned on the alert_fast option to see the [Drop] keyword on each dropped
event line.

What approaches have you followed to have that fixed? (Perhaps modifying
barnyard source code?)

Thanks in advance.

Josep Román

<<attachment: winmail.dat>>

-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2005.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Current thread: