Snort mailing list archives

Re: Snort/Barnyard Error


From: Joel Esler <jesler () sourcefire com>
Date: Fri, 21 Aug 2009 10:04:07 -0400

Clarification, are you using barnyard, or barnyard2?
If the former, please use the latter.

J

On Fri, Aug 21, 2009 at 9:32 AM, Richard Lichvar <rlichvar () sainc com> wrote:

 First of all, I’m not sure the original post came through correctly so
I’m reposting. (Think I let outlook autofill and got the –request address.
My apologies.)

Second, I'm a newbie to Snort not having worked with it in several years
(and then just dabbling in it) so I'm just coming up to speed. Also, since
this has to do with barnyard, I’m not sure this is the correct forum in
which to post this.

Now, to the problem:

Our Snort/IDS/syslogs (we use Splunk to collect/view) are getting filled-up
with a barnyard 2629 warning "unable to extract timestampe file extension
from 'snort.log.nnnnnn.’ How we can fix this?

Many thanks in advance for your help!

RichLich




------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
trial. Simplify your report design, integration and deployment - and focus
on
what you do best, core application coding. Discover what's new with
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


-- Joel Esler | Sourcefire | Google Voice: 302-223-5974
------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
trial. Simplify your report design, integration and deployment - and focus on 
what you do best, core application coding. Discover what's new with 
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Current thread: