Snort mailing list archives
Re: trying this again (UNCLASSIFIED)
From: beenph <beenph () gmail com>
Date: Fri, 14 Dec 2012 20:18:26 -0500
On Fri, Dec 14, 2012 at 11:42 AM, Cass, Mark A CTR (US) < mark.a.cass2.ctr () mail mil> wrote:
Classification: UNCLASSIFIED Caveats: NONE Thank you for the reply. Let me see if I got this straight...
Unfortunaly i think some things where not understood properly and i will try to reclarify them.
I'll need to specify the -f option for barnyard2 and tell it the prefix
naming convention of the files it needs to input to log to mysql database? Yes if in your snort.conf file you have output unified2: filename snort.log, limit 128 Then the barnyard2 -f argument needs to be snort.log
The reason for the barnyard2 aborting was because the test rule did not
have a "rev:xxx" at the top >of the text file? Not at the top of the file but in the rule body of your test rule icmp any any -> any any (msg:"blabla test rule"; sid:100000001;) |---------------RULE BODY-------------------| Should have been icmp any any -> any any (msg:"blabla test rule"; sid:100000001; rev:1;) |---------------RULE BODY-------------------|
So when I downloaded the new rules from pulled pork, and commented out the
test rule, should the rules downloaded from pulled pork not have had a revision with it already?
I'm going to have to go into a thousand files >and manually add "rev:(some number)" to them all in order for it to work? That seems really ridiculous. And would I have to do this manually every
time the rules are updated?
The last thing about the -G and -S options, I'm totally lost. I'm just
running it how the guide told me to, with those options. You're saying that at this point, the -G -S options are not allowing barnyard2 to write the data to mysql?
Thank you,
------------------------------------------------------------------------------ LogMeIn Rescue: Anywhere, Anytime Remote support for IT. Free Trial Remotely access PCs and mobile devices and provide instant support Improve your efficiency, and focus on delivering more value-add services Discover what IT Professionals Know. Rescue delivers http://p.sf.net/sfu/logmein_12329d2d
_______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- trying this again (UNCLASSIFIED) Cass, Mark A CTR (US) (Dec 13)
- Re: trying this again (UNCLASSIFIED) Rhoades . Jon (Dec 13)
- Re: trying this again (UNCLASSIFIED) Peter Bates (Dec 13)
- Re: trying this again (UNCLASSIFIED) Cass, Mark A CTR (US) (Dec 14)
- Re: trying this again (UNCLASSIFIED) beenph (Dec 14)
- Re: trying this again (UNCLASSIFIED) Cass, Mark A CTR (US) (Dec 14)
- Re: trying this again (UNCLASSIFIED) Peter Bates (Dec 14)
- Re: trying this again (UNCLASSIFIED) beenph (Dec 14)
- Re: trying this again (UNCLASSIFIED) beenph (Dec 14)
- Re: trying this again (UNCLASSIFIED) Rhoades . Jon (Dec 13)