Snort mailing list archives

Re: Error compiling snort with snortsam


From: Ashraf Ali <ashrafali.ibs () gmail com>
Date: Fri, 19 Apr 2013 10:07:55 +0530

Hi All,

I am new to IDS/Linux , So could any body pls explain me in a bit detail ,
on how to configure the barnyard2/snortsam to block a Pix firewall if some
alert triggers,


Regards,
Ashraf


On Wed, Apr 17, 2013 at 10:23 PM, beenph <beenph () gmail com> wrote:

On Wed, Apr 17, 2013 at 12:26 PM, Joel Esler <jesler () sourcefire com>
wrote:
On Apr 17, 2013, at 11:43 AM, "Castle, Shane" <scastle () bouldercounty org

wrote:

Snortsam is no longer supported as an output module on Snort. Use
Barnyard2,
which has snortsam support built-in. In fact, the only two output options
for Snort any more are the unified2 output and syslog, I understand. BY2
will read the unified2 output and do all the cool things for output that
used to be built into snort.

This change is now so old that it's unlikely that any of the Snort folks
will respond.


We never supported it as an add on anyway.  This was always maintained by
the community outside of the standard tarball.  I think the approach to
have
the functionality in barnyard2 is a much smarter way of doing it.

--

And as a pointer,

 information concerning barnyard2 snortsam output plugin can be found here.

https://github.com/firnsy/barnyard2/blob/master/doc/README.snortsam

Cheers,
-elz

------------------------------------------------------------------------------
Precog is a next-generation analytics platform capable of advanced
analytics on semi-structured data. The platform includes APIs for building
apps and a phenomenal toolset for data science. Developers can use
our toolset for easy data analysis & visualization. Get a free account!
http://www2.precog.com/precogplatform/slashdotnewsletter
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: