-
Notifications
You must be signed in to change notification settings - Fork 189
FATAL ERROR: Duplicate entry on INSERT INTO event #120
Comments
InnoDB or MyIASM? Seem's like your ither using MyIASM or running two by2 instance with the Make sure you do not run a process in console and one in background for Cheers, On Tue, Oct 7, 2014 at 4:57 PM, Claudio Kuenzler notifications@github.com
|
Hey binf,
... where "db" is the db name by2 is supposed to write into. If you mean two by2 processes with "two by2 instance with the same sid" then I'm certain, that only one process was started. I verified this while tailing the syslog and in another terminal verified the number of processes. |
Here's additional information when I start barnyard (I emptied the database again). Hope this helps.
At the same time I was checking for the processes (only one is running... until the FATAL ERROR hits by2):
|
OK, I think I found something very interesting while I was stracing barnyard. It occurred to me, that two mysql connections were established by by2. I enabled the general query log and this confirmed it to me. I attach the output below. You see connection number 47 from by2 does the job with querying existing signatures, etc... but then suddenly another Connect arrives (48) which basically does the same queries once again. Note that connection 47 is still connected...
|
You have two process running at the same time. Barnyard2 by it self only generate one connection unless you defined two Cheers. On Wed, Oct 8, 2014 at 2:47 PM, Claudio Kuenzler notifications@github.com
|
Hey binf, I started barnyard like this, so there is no second process (as documented above):
However your hint about the "two database output plugin" was just excellent! Indeed I have uncommented both mysql entries in /etc/barnyard2.conf:
So once I commented the "log" line again, barnyard ran through without error and keeps running :-) Thanks a lot for your help and your time for responding! |
Hi,
I tried to use barnyard2 together with suricata 2.0.4 but everytime barnyard wants to write into the mysql database, it fails:
This was with barnyard2 2.1.13 and with an empty database. I also tried it with barnyard 2.1.12 but with the a similar problem:
My event table looks like this once barnyard2 stopped running (maybe this gives you a hint, but as I said, the database was empty except of the imported schema):
Any help or idea how to fix that is greatly appreciated.
OS: Debian 7 Wheezy (MySQL 5.5 installed through apt)
Suricata IDS 2.0.4 installed from source
Barnyard2 2.1.13 (and 2.1.12) installed from https://github.com/firnsy/barnyard
The text was updated successfully, but these errors were encountered: