Skip to content

Option to disable appending interface to hostname. #11

@CyberTaoFlow

Description

@CyberTaoFlow

Noticed the note in the source about barnyard wanting the hostname with interface like
hostname:if#

I have not experienced this problem however even when using your awesome fork of by2 with a command line like:

/usr/local/bin/barnyard2 -D -c /etc/sensor/rules/the.conf -d /var/log/snort/internal/ -S /etc/sensor/rules/sid-msg.map -f snort-unified.log -w /var/log/snort/internal/barnyard.book -i eth2 --pid-path /tmp/barnyard

In any case when testing meer and discovering the different sensor naming convention in the DB it led an associate and I to code a workaround.

eventhorizon5@d18f375

I would submit a pull but my associate owns that account and he is no longer with the company so if the commit above seems sane to you would you be ok with merging in the functionality?

Just want to avoid custom builds if possible and also allow switching to meer as a drop in replacement (no need to register a new sensor in the table).

I can also fork and then request a pull if that is what you would prefer.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions