Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Snort-users] multiple instances of snort and barnyard |
|---|---|
| Date: | Wed, 23 Aug 2006 12:05:04 -0400 |
You can create different directories for each instance, Have all the unified filed for each instance of Snort log to its own directory, then have 3 instances of barnyard, each reading from it's respective directory. Joel On Wed, Aug 23, 2006 at 09:41:05AM -0500, Spencer Anderson apparently sent me:
I run several instances of Snort on SuSE Linux (to monitor traffic on 2-3 NICs) and I have been logging directly to a MySQL database. I would like to start using the unified output and barnyard. I have it working for the most part, the problem is I have a unified output file for each interface that I have snort listening on and I can't get multiple instances of barnyard to run in continuous mode to process each log file. I'd prefer to run barnyard in batch mode in 10 minute intervals on each log file, I can't seem to do that either without restarting snort each time after I run barnyard to create a new unified log file. Is there a way to run barnyard in batch mode so that each time it's run against a file it only processes events that it hasn't processed before? Or, is there a way to have multiple continuous instances of barnyard running so each instance can maintain its corresponding snort unified log file? Or, is there a better way to have each event captured by snort associated with the network interface it was detected on? SuSE Enterprise 9 Snort 2.4.5 Barnyard 0.2.0 Thanks, Spencer ------------------------------------------------------------------------- Using Tomcat but need to do more? Need to support web services, security? Get stuff done quickly with pre-integrated technology to make your job easier Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642 _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
+---------------------------------------------------------------------+ joel esler senior security consultant 1-706-627-2101 Sourcefire Security for the /Real/ World -- http://www.sourcefire.com Snort - Open Source Network IPS/IDS -- http://www.snort.org gpg key: http://demo.sourcefire.com/jesler.pgp.key aim:eslerjoel ymsg:eslerjoel gtalk:eslerj +---------------------------------------------------------------------+ ------------------------------------------------------------------------- Using Tomcat but need to do more? Need to support web services, security? Get stuff done quickly with pre-integrated technology to make your job easier Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642 _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-users] frag3 order question, Gentoo-Wally |
|---|---|
| Next by Date: | Re: [Snort-users] frag3 order question, Joel Esler |
| Previous by Thread: | [Snort-users] multiple instances of snort and barnyard, Spencer Anderson |
| Next by Thread: | Re: [Snort-users] multiple instances of snort and barnyard, Paul Schmehl |
| Indexes: | [Date] [Thread] [Top] [All Lists] |