Snort mailing list archives

Re: Barnyard2 timestamp resolution


From: "Asad, Hafiz ul" <Hafiz-ul.Asad () city ac uk>
Date: Wed, 24 Aug 2016 13:54:45 +0000

Baryanrd2 would save this as "2016-07-25 11:25:31" ignoring the ".355". Is there a workaround so that Barnyard2 stores 
the alerts with a millisecond resolution?


Asad

________________________________
From: wkitty42 () windstream net <wkitty42 () windstream net>
Sent: Wednesday, August 24, 2016 2:40:31 PM
To: snort-users () lists sourceforge net
Subject: Re: [Snort-users] Barnyard2 timestamp resolution

On 08/24/2016 09:15 AM, Asad, Hafiz ul wrote:
Snort Users,


I wonder whether Barnyard2 timestamp, in the mysql database, could be for example

"2016-07-25 11:25:31.355". Currently, it seems, the timestamp resolution is in
seconds and I want that to be in milli-seconds. Could anyone help?

ummm... that ".355" on the end is milliseconds...

--
  NOTE: No off-list assistance is given without prior approval.
        *Please keep mailing list traffic on the list* unless
        private contact is specifically requested and granted.

------------------------------------------------------------------------------
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!
------------------------------------------------------------------------------
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: