Snort mailing list archives

Re: Barnyard2 configuration and event generation


From: waldo kitty <wkitty42 () windstream net>
Date: Wed, 19 Dec 2012 20:41:27 -0500

On 12/19/2012 15:05, Steve Marotta wrote:
Ah, excellent. So what I'm interested in are the alerts. I looked in /var/log/snort as well as the directory I 
specified as my logfile directory, and I didn't see any recent alert files. Did I inadvertently disable them in my 
conf file, or is there another place I should be looking?

there is only one alert file that i'm aware of... it is not serialized like the 
pcaps and u2 files... at least not that i've ever seen in the years i've been 
using snort...

as for disabling it, that's something i haven't yet found out... in our 
installs, it seems to be a default enabled file...


------------------------------------------------------------------------------
LogMeIn Rescue: Anywhere, Anytime Remote support for IT. Free Trial
Remotely access PCs and mobile devices and provide instant support
Improve your efficiency, and focus on delivering more value-add services
Discover what IT Professionals Know. Rescue delivers
http://p.sf.net/sfu/logmein_12329d2d
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: