Snort mailing list archives

does the aciddb output plugin in barnyard rc2 build 11 work?


From: Mark Rowlands <mark.rowlands () minmail net>
Date: Sun, 7 Jul 2002 15:21:40 +0200

Snort V1.9.0beta build 171
Barnyard V0.1.0-rc2 build 11

FreeBSD pcmarpxy.tninet.se 4.6-STABLE FreeBSD 4.6-STABLE #2: Thu Jun 27 
18:26:51 CEST 2002    i386


both compiled from source with enable-mysql


-*> Barnyard! <*-
Version 0.1.0-rc2 (Build 11)
By Andrew R. Baker (andrewb () snort org)
and Martin Roesch (roesch () sourcefire com, www.snort.org)

Loading Data Processors...
dp_alert loaded
dp_log loaded
dp_stream_stat loaded
Loading Built-in Output Plugins...
Fast Alert plugin initialized
AlertSyslog initialized
Log Dump plugin initialized
LogPcap initialized
AlertCSV initialized
Parsing Config file: /rules/barnyard.conf
WARNING /rules/barnyard.conf(7) => Unknown output plugin "alert_acid_db" 
referenced, ignoring!
WARNING /rules/barnyard.conf(8) => Unknown output plugin "log_acid_db" 
referenced, ignoring!Archive Directory is NULL
Config File =/rules/barnyard.conf
Log Dir=/var/log/snort
Spool Dir=/logs/
Spool File=snort.alert.1025981436
Waldo File is NULL
Sid File=/rules/sid-msg.map
Gen File=/rules/gen-msg.map
Hostname=localhost
Interface=xl1
Filter=not port 22
Record Number: 0
Log Flag: 0
Verbosity Level=0
File Arg Start: 0
One shot mode enabled
Dry Run mode enabled
commandline: barnyard -c /rules/barnyard.conf -d /logs/ -g /rules/gen-msg.map 
-s /rules/sid-msg.map -f snort.alert.1025981436 -o -R 

************************************

barnyard.conf

config hostname: localhost
config interface: xl1
config filter: not port 22
processor dp_alert
processor dp_log
processor dp_stream_stat 
output alert_acid_db: mysql, sensor_id 6, database snort, server localhost, 
user root
output log_acid_db: mysql, sensor_id 6, database snort, server localhost, user 
root,password XXXXXX detail full
       
*************************************



-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
We have stuff for geeks like you.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: