Snort mailing list archives
Re: Barnyard2 configuration and event generation
From: waldo kitty <wkitty42 () windstream net>
Date: Wed, 19 Dec 2012 20:41:27 -0500
On 12/19/2012 15:05, Steve Marotta wrote:
Ah, excellent. So what I'm interested in are the alerts. I looked in /var/log/snort as well as the directory I specified as my logfile directory, and I didn't see any recent alert files. Did I inadvertently disable them in my conf file, or is there another place I should be looking?
there is only one alert file that i'm aware of... it is not serialized like the pcaps and u2 files... at least not that i've ever seen in the years i've been using snort... as for disabling it, that's something i haven't yet found out... in our installs, it seems to be a default enabled file... ------------------------------------------------------------------------------ LogMeIn Rescue: Anywhere, Anytime Remote support for IT. Free Trial Remotely access PCs and mobile devices and provide instant support Improve your efficiency, and focus on delivering more value-add services Discover what IT Professionals Know. Rescue delivers http://p.sf.net/sfu/logmein_12329d2d _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- Barnyard2 configuration and event generation Steve Marotta (Dec 19)
- Re: Barnyard2 configuration and event generation beenph (Dec 19)
- Re: Barnyard2 configuration and event generation Steve Marotta (Dec 19)
- Re: Barnyard2 configuration and event generation beenph (Dec 19)
- Re: Barnyard2 configuration and event generation Steve Marotta (Dec 19)
- Re: Barnyard2 configuration and event generation waldo kitty (Dec 19)
- Alerts are almost entirely "Executable Code was Detected" Steve Marotta (Dec 20)
- Re: Alerts are almost entirely "Executable Code was Detected" Joel Esler (Dec 20)
- Re: Barnyard2 configuration and event generation Steve Marotta (Dec 19)
- Re: Barnyard2 configuration and event generation beenph (Dec 19)