I think I would let snort do both unified and syslog output.
The main reason for having barnyard write to SQL db is performance and
latency.
I think snort-> direct to syslog should be non-blocking and won't hurt
performance.
-------------------------------------------------------
This SF.Net email is sponsored by: New Crystal Reports XI.
Version 11 adds new functionality designed to reduce time involved in
creating, integrating, and deploying reporting solutions. Free runtime info,
new features, or free trial, at: http://www.businessobjects.com/devxi/728
|