Snort mailing list archives
barnyard: alert_syslog2 not working
From: "Botwick, Jason (Genworth, Contractor)" <Jason.Botwick () genworth com>
Date: Thu, 7 Oct 2004 19:00:03 -0400
Here is my barnyard.conf file config hostname: x.x.x.x config interface: x output alert_syslog2: severity: NOTICE; facility: LOCAL1; #output alert_syslog: LOG_LOCAL2 LOG_ALERT LOG_NDELAY Here are the lines I added to the syslog.conf file: local1.* /var/log/barnyard.log local2.* /var/log/barnyard2.log I SIGHUP'd both syslogd and barnyard. I even tried rebooting once, but Running the command: barnyard -o snort.eth1.alert.1097060734 -c /etc/snort/barnyard.conf Produces no output in /var/log/barnyard.log I have Snort configured to output in unified format. I know that this is working because I can get Barnyard to log to a database, and also the alert_syslog plugin works fine (using the commented directive above). Any ideas why the old syslog plugin works, but the new one doesn't? What am I forgetting?
Current thread:
- barnyard: alert_syslog2 not working Botwick, Jason (Genworth, Contractor) (Oct 07)
- Re: barnyard: alert_syslog2 not working Andrew R. Baker (Oct 12)