This address has been bouncing for well over a year. Do the administrators
of this list think it might be possible to purge the address from the list?
------------ Forwarded Message ------------
Date: January 27, 2006 10:49:02 PM -0600
From: System Administrator <postmaster@utdevs08.utdallas.edu>
To: "Schmehl, Paul L" <pauls@utdallas.edu>
Subject: Undeliverable:Re: [Snort-users] barnyard
Your message
To: Brian Krusic; snort-users@lists.sourceforge.net
Subject: Re: [Snort-users] barnyard
Sent: Fri, 27 Jan 2006 22:21:16 -0600
did not reach the following recipient(s):
anjah@imedia.fr on Fri, 27 Jan 2006 22:26:51 -0600
The e-mail account does not exist at the organization this message
was sent to. Check the e-mail address, or contact the recipient
directly to find out the correct address.
<imedia-hvj182q6.imedia.net #5.1.1>
---------- End Forwarded Message ----------
Paul Schmehl (pauls@utdallas.edu)
Adjunct Information Security Officer
University of Texas at Dallas
AVIEN Founding Member
http://www.utdallas.edu/
--- Begin Message ---
|
Subject: |
Undeliverable:Re: [Snort-users] barnyard |
|
Date: |
Fri, 27 Jan 2006 22:49:02 -0600 |
Your message
To: Brian Krusic; snort-users@lists.sourceforge.net
Subject: Re: [Snort-users] barnyard
Sent: Fri, 27 Jan 2006 22:21:16 -0600
did not reach the following recipient(s):
anjah@imedia.fr on Fri, 27 Jan 2006 22:26:51 -0600
The e-mail account does not exist at the organization this message
was sent to. Check the e-mail address, or contact the recipient
directly to find out the correct address.
<imedia-hvj182q6.imedia.net #5.1.1>
Reporting-MTA: dns; UTDEVS08.campus.ad.utdallas.edu
Final-Recipient: RFC822; anjah@imedia.fr
Action: failed
Status: 5.1.1
X-Supplementary-Info: <imedia-hvj182q6.imedia.net #5.1.1>
X-Display-Name: anjah@imedia.fr
--- Begin Message ---
|
Subject: |
Re: [Snort-users] barnyard |
|
Date: |
Fri, 27 Jan 2006 22:21:16 -0600 |
--On January 27, 2006 4:47:14 PM -0800 Brian Krusic <brian@krusic.com>
wrote:
My command line;
barnard -c /usr/local/barnyard/etc/barnyard.conf -d /var/log/snort -g
/usr/local/snort/etc/gen-msg.map -s /usr/local/snort/etc/sid-msg.map -f
snort.alert
You can run barnyard with this:
barnyard -c /path/to/conffile -d /path/to/logdir -f logfilename
If you do this in the barnyard.conf file
config sid-msg-map: /path/to/sid-msg.map
config gen-msg=map: /path/to/gen-msg.map
config class-file: /path/to/classification.config
This is not in the docs, but it is in the source code. (I'm the FreeBSD
port maintainer for barnyard.)
Barnyard can output directly to a text file, to a pcap file, to a database
(mysql or postgresql) or to sguil.
Paul Schmehl (pauls@utdallas.edu)
Adjunct Information Security Officer
University of Texas at Dallas
AVIEN Founding Member
http://www.utdallas.edu/
-------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc. Do you grep through log files
for problems? Stop! Download the new AJAX search engine that makes
searching your log files as easy as surfing the web. DOWNLOAD SPLUNK!
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=103432&bid=230486&dat=121642
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users
--- End Message ---
--- End Message ---