Hi list,
I just installed Sguil0.5.3 with Barnyard0.2 in
FreeBSD 5.3 Stable. Squild started successfully, but
Barnyard failed with core dump. The error is:
# barnyard -c barnyard.conf -d /nsm -g gen-msg.map -s
sid-msg.map -f snort.log -w -waldo.file &
[3] 1413
root@at [6:23pm] [...etc/snort]# Barnyard Version
0.2.0 (Build 32)
Opened spool file '/nsm/snort.log.1102406776'
OpSguil_Start
Connect from 127.0.0.1:57448 sock11
Validating sensor access: 127.0.0.1 :
ALLOWED
Sensor Data Rcvd: RTEvent
|||system-info|localhost||Barnyard started.||||||||
SYSTEM INFO: {} {} system-info localhost {} {Barnyard
started.} {} {} {} {} {} {} {} {}
No clients to send info msg to.
Sensor Data Rcvd: RTEvent
|||system-info|localhost||Database Server:
localhost.||||||||
SYSTEM INFO: {} {} system-info localhost {} {Database
Server: localhost.} {} {} {} {} {} {} {} {}
No clients to send info msg to.
Sensor Data Rcvd: RTEvent
|||system-info|localhost||Database Next CID:
1.||||||||
SYSTEM INFO: {} {} system-info localhost {} {Database
Next CID: 1.} {} {} {} {} {} {} {} {}
No clients to send info msg to.
Sensor Data Rcvd: RTEvent
|0|3|unknown|localhost|2004-12-07 08:18:55|2|1|tag:
Tagged Packet||||||1|0|
Alert Received: 0 3 unknown localhost {2004-12-07
08:18:55} 2 1 {tag: Tagged Packet} {} {} {} {} {} 1 0
No clients to send alert to.
Sensor Data Rcvd:
Sensor Cmd Unkown (sock11):
Socket sock11 closed
[3] Segmentation fault barnyard -c
barnyard.conf -d /nsm -g gen-msg.map -s sid-msg.map -f
snort.log -w ... (core dumped)
root@at [6:24pm] [...etc/snort]#
The command to start squild is just simply ./squild
The configuration of barnyard is shown as below:
config hostname: at #"at" is the name of the Baryard
server.
config interface: tun0
config filter: not port 22
output alert_fast
output log_dump
output sguil: mysql, sensor_id 0, database sguildb,
server localhost,\
user sguil, password mypasswd, sguild_host localhost,
sguild_port 7736
Is there any suggestion to fix this error?
Your comment is very appreciated.
Thanks
Sam
__________________________________
Do you Yahoo!?
Yahoo! Mail - 250MB free storage. Do more. Manage less.
http://info.mail.yahoo.com/mail_250
-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now.
http://productguide.itmanagersjournal.com/
|