logo       

Choosing A Webhost:
A web hosting service is a type of Internet hosting service that allows individuals and organizations to provide their own website accessible via the World Wide Web. Web hosts are companies that provide space on a server they own for use by their clients as well as providing Internet connectivity, typically in a data center. Web hosts can also provide data center space and connectivity to the Internet for servers they do not own to be located in their data center, called colocation. more...

Barnyard not populating opt table: msg#00000

security.ids.snort.barnyard.user

Subject: Barnyard not populating opt table

I noticed that since installing Barnyard we're not
seeing any TCP options when viewing events with BASE.
I checked the snort.opt table and sure enough it was
empty. This was a fresh Snort/Barnyard install with
Barnyard running from the start. I reconfigured Snort
to log directly to the database, and immediately
started seeing data in the opt table. So, it's fairly
certain that the problem is with Barnyard or more
likely my configuration.

Here's the config.

config daemon
config localtime
config hostname: ranger
config interface: eth1
config sid-msg-map: /etc/snort/rules/sid-msg.map
config gen-msg-map: /etc/snort/rules/gen-msg.map
config class-file:
/etc/snort/rules/classification.config
output alert_acid_db: mysql, database snort, server
localhost, user snort, password snort, detail full
output log_acid_db: mysql, database snort, server
localhost, user snort, password snort, detail full

And here is how it's being started.

/usr/local/bin/barnyard -c
/etc/snort/barnyard/barnyard.conf -d /var/log/snort -f
snort.log -w /var/log/snort/waldo.barnyard -a
/var/log/snort/archive

Also, it has never been completely clear if the output
alert_acid_db line is necessary. I have run Barnyard
without that line and it seemed to work fine execept
for the problem noted above. It appears as though the
log files incorporate all of the information in the
alert files, so I would not think that it should be
necessary.

We're running Snort-2.4.2, Barnyard-0.2.0, and mysql
Ver 14.7

Any assistance would be appreciated.

--Dave




______________________________________________________
Yahoo! for Good
Donate to the Hurricane Katrina relief effort.
http://store.yahoo.com/redcross-donate3/



-------------------------------------------------------
This SF.Net email is sponsored by:
Power Architecture Resource Center: Free content, downloads, discussions,
and more. http://solutions.newsforge.com/ibmarch.tmpl


<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

Recently Viewed:
qnx.openqnx.dev...    gcc.libstdc++.c...    solaris.opensol...    information-ret...    misc.misterhous...    web.catalyst.ge...    apache.webservi...    redhat.release....    hardware.lirc/2...    kernel.autofs/2...    technology.sust...    linux.vdr/2003-...    editors.lyx.gen...    org.user-groups...    netbsd.devel.pk...    xdg.devel/2004-...    version-control...    jakarta.slide.d...    debian.packages...    creativecommons...    ports.ppc.embed...    bug-tracking.bu...   
Home | blog view | USPTO Patent Archive | advertise | OSDir is an inevitable website. super tiny logo

Free Magazines

Cisco News
Receive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business.
subscribe

Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field.
subscribe

The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business.
subscribe

Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company.
subscribe

Total Telecom Total Telecom is "The Economist of the communications industry".
subscribe

Navigation