Snort mailing list archives

Re: Barnyard2 error


From: Abid Ayoub <abid.ayoub () gmail com>
Date: Wed, 24 Jul 2013 16:47:43 +0200

Hi,
i did´t understand what what do you mean exactly
but , if you mean that i am runnung snort or barnyard2 on background , the
answer is no.
Abid


2013/7/24 Abid Ayoub <abid.ayoub () gmail com>

Hi,

i did´t understand what what do you mean exactly
but , if you mean that i am runnung snort or barnyard2 on background , the
answer is no.

Abid


2013/7/24 beenph <beenph () gmail com>

On Wed, Jul 24, 2013 at 10:15 AM, Abid Ayoub <abid.ayoub () gmail com>
wrote:
Hello,

when i run the "barnyard2" with the next command:

/usr/local/bin/barnyard2 -c /usr/local/snort/etc/barnyard2.conf -d
/var/log/snort -f snort.u2 -w /var/log/snort/barnyard2.waldo

I got:

Running in Continuous mode
        --== Initializing Barnyard2 ==--
Initializing Input Plugins!
Initializing Output Plugins!
Parsing config file "/usr/local/snort/etc/barnyard2.conf"

+[ Signature Suppress list ]+
----------------------------
+[No entry in Signature Suppress List]+
----------------------------
+[ Signature Suppress list ]+
Barnyard2 spooler: Event cache size set to [2048]
Log directory = /var/log/barnyard2
INFO database: Defaulting Reconnect/Transaction Error limit to 10
INFO database: Defaulting Reconnect sleep time to 5 second
[SignatureReferencePullDataStore()]: No Reference found in database ...
database: compiled support for (mysql)
database: configured to use mysql
database: schema version = 107
database:           host = localhost
database:           user = root
database:  database name = snort
database:    sensor name = localhost:eth1
database:      sensor id = 1
database:     sensor cid = 1
database:  data encoding = hex
database:   detail level = full
database:     ignore_bpf = no
database: using the "log" facility
        --== Initialization Complete ==--
  ______   -*> Barnyard2 <*-
 / ,,_  \  Version 2.1.13 (Build 327)
 |o"  )~|  By Ian Firns (SecurixLive): http://www.securixlive.com/
 + '''' +  (C) Copyright 2008-2013 Ian Firns <firnsy () securixlive com>
WARNING: Ignoring corrupt/truncated waldofile
'/var/log/snort/barnyard2.waldo'
Waiting for new spool file

So, how can i solve this problem ? any idea ?

Hi Abid,

Seen's to be running fine at this point? You have an issue?

-elz



------------------------------------------------------------------------------
See everything from the browser to the database with AppDynamics
Get end-to-end visibility with application monitoring from AppDynamics
Isolate bottlenecks and diagnose root cause in seconds.
Start your free trial of AppDynamics Pro today!
http://pubads.g.doubleclick.net/gampad/clk?id=48808831&iu=/4140/ostg.clktrk
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: