Snort mailing list archives

display tcp payload with BASE


From: Link Ragus <linkragus () gmail com>
Date: Thu, 3 May 2012 00:52:45 +0200

Hello all,

I am new to Snort, I use Snort2.9.2.2>barnyard2>MySQL>BASE, and  have
a probleme: I can't display the tcp payload with BASE. So how can I
display tcp payload?


Thanks!



barnyard2.conf:

output database: log, mysql, user=snortuser password=snortpassword
dbname=snort host=localhost detail=full


snort.conf:

output unified2: filename snort.log, limit 128



Running in Continuous mode

        --== Initializing Barnyard2 ==--
Initializing Input Plugins!
Initializing Output Plugins!
Parsing config file "/etc/snort/barnyard2.conf"
ERROR: Unable to open SID file '/etc/snort/sid-msg.map' (No such file
or directory)
Log directory = /var/log/barnyard2
Node unique name is:

Last event seen for sid 4 was 9


database: compiled support for (mysql)
database: configured to use mysql
database: schema version = 107
database:           host = localhost
database:           user = snortuser
database:  database name = snort
database:    sensor name =
database:      sensor id = 4
database:     sensor cid = 10
database:  data encoding = hex
database:   detail level = full
database:     ignore_bpf = no
database: using the "log" facility
------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: