|
|
| <prev next> |
Choosing A Webhost: |
Barnyard not populating opt table: msg#00000security.ids.snort.barnyard.user
I noticed that since installing Barnyard we're not seeing any TCP options when viewing events with BASE. I checked the snort.opt table and sure enough it was empty. This was a fresh Snort/Barnyard install with Barnyard running from the start. I reconfigured Snort to log directly to the database, and immediately started seeing data in the opt table. So, it's fairly certain that the problem is with Barnyard or more likely my configuration. Here's the config. config daemon config localtime config hostname: ranger config interface: eth1 config sid-msg-map: /etc/snort/rules/sid-msg.map config gen-msg-map: /etc/snort/rules/gen-msg.map config class-file: /etc/snort/rules/classification.config output alert_acid_db: mysql, database snort, server localhost, user snort, password snort, detail full output log_acid_db: mysql, database snort, server localhost, user snort, password snort, detail full And here is how it's being started. /usr/local/bin/barnyard -c /etc/snort/barnyard/barnyard.conf -d /var/log/snort -f snort.log -w /var/log/snort/waldo.barnyard -a /var/log/snort/archive Also, it has never been completely clear if the output alert_acid_db line is necessary. I have run Barnyard without that line and it seemed to work fine execept for the problem noted above. It appears as though the log files incorporate all of the information in the alert files, so I would not think that it should be necessary. We're running Snort-2.4.2, Barnyard-0.2.0, and mysql Ver 14.7 Any assistance would be appreciated. --Dave ______________________________________________________ Yahoo! for Good Donate to the Hurricane Katrina relief effort. http://store.yahoo.com/redcross-donate3/ ------------------------------------------------------- This SF.Net email is sponsored by: Power Architecture Resource Center: Free content, downloads, discussions, and more. http://solutions.newsforge.com/ibmarch.tmpl
|
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Next by Date: | Re: Barnyard not populating opt table, David Humes |
|---|---|
| Next by Thread: | Re: Barnyard not populating opt table, David Humes |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
Free MagazinesCisco NewsReceive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business. subscribe Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field. subscribe The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business. subscribe Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company. subscribe Total Telecom Total Telecom is "The Economist of the communications industry". subscribe |