Snort mailing list archives
Barnyard2 configuration and event generation
From: Steve Marotta <smarotta () cra com>
Date: Wed, 19 Dec 2012 11:38:07 -0500
I'm using Barnyard2 to read Snort unified log files and generate some text log of events found in those logs. The problem is, all I'm getting is that there's a bunch of TCP packets. I was hoping for more specific information like ARP, HTTP, event/transaction information, that sort of thing. Snort seemed to have things categorized nicely, but I couldn't see the specific event list. All I want is a text log with detailed, specific events that give an idea of what is going on. The command I'm running to read the logs is: barnyard2 -c /usr/local/snort/etc/barnyard2.conf -o test-attack1.snort.u2.1355871919 Is there another option I should try? THIS MESSAGE IS INTENDED FOR THE USE OF THE PERSON TO WHOM IT IS ADDRESSED. IT MAY CONTAIN INFORMATION THAT IS PRIVILEGED, CONFIDENTIAL AND EXEMPT FROM DISCLOSURE UNDER APPLICABLE LAW. If you are not the intended recipient, your use of this message for any purpose is strictly prohibited. If you have received this communication in error, please delete the message and notify the sender so that we may correct our records. ------------------------------------------------------------------------------ LogMeIn Rescue: Anywhere, Anytime Remote support for IT. Free Trial Remotely access PCs and mobile devices and provide instant support Improve your efficiency, and focus on delivering more value-add services Discover what IT Professionals Know. Rescue delivers http://p.sf.net/sfu/logmein_12329d2d _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- Barnyard2 configuration and event generation Steve Marotta (Dec 19)
- Re: Barnyard2 configuration and event generation beenph (Dec 19)
- Re: Barnyard2 configuration and event generation Steve Marotta (Dec 19)
- Re: Barnyard2 configuration and event generation beenph (Dec 19)
- Re: Barnyard2 configuration and event generation Steve Marotta (Dec 19)
- Re: Barnyard2 configuration and event generation waldo kitty (Dec 19)
- Alerts are almost entirely "Executable Code was Detected" Steve Marotta (Dec 20)
- Re: Alerts are almost entirely "Executable Code was Detected" Joel Esler (Dec 20)
- Re: Barnyard2 configuration and event generation Steve Marotta (Dec 19)
- Re: Barnyard2 configuration and event generation beenph (Dec 19)