-
Notifications
You must be signed in to change notification settings - Fork 189
Barnyard2 does not read the output of snort - mysql empty #89
Comments
It's better with
my apologies |
You can also close it your self if you do not mind. Cheers, On Thu, May 23, 2013 at 5:13 AM, Tmolle notifications@github.com wrote:
|
I have the same problem, alerts do not want to get into the database. Almost same as Tmolle. I've been using the syntax snort-q-u snort-g snort-c / etc / snort / snort.conf-i eth0-D ... but database still empty. How do I know that barnyrad2 work well to loging alerts? and how use of waldo file, using var / log / snort / barnyard.waldo or var/log/barnyard2/barnyard2.waldo? Thanks you |
If you read the thread you would see how this was fixed, you can also read Cheers. On Mon, Jul 29, 2013 at 7:58 PM, gegez notifications@github.com wrote:
|
i have a similair problem. its not writing to database Sep 1 16:39:06 snort barnyard2: +[ Signature Suppress list ]+Sep 1 16:39:06 snort barnyard2: +[No entry in Signature Suppress List]+ Sep 1 16:40:40 snort barnyard2: Node unique name is: snort:ens32 but the file snort.log.1409584351 is being written to, i have a constant ping running. |
Same answer. On Mon, Sep 1, 2014 at 11:46 AM, shorif2000 notifications@github.com
|
Where can I find the answer??? There are only questions on this thread (as well as on any thread about snort...) |
I really don't think this was solved by running snort in daemon mode (which is what Tmolle did when he said it "worked better" -> notice he didn't say it fixes it). I have the same issue, snort is capturing packets and processing alerts, if I run I have been following the official guide which does have some deviations that I was able to fix, the only hint that I can see now is that the waldo file is corrupted/truncated:
My waldo file is empty (as per the instructions in that guide), and after changing permissions and ownerships to everything I could think of (snort and barnyard2 run as snort:snort and my waldo file is owned by snort:snort) I went to the source code, here's what I found:
I understand the logic behind it as: if the number of bytes that we read from the waldo file does not match the size of the WaldoData object then the file is corrupted or empty. I suppose that to those whom this worked out of the box were maybe using a different build or followed a different set of instructions, but if someone is more familiar with barnyard2 please chip in, I strongly believe that running snort in daemon mode does not fix the issue of barnyard not reading snort logs Edit: I should also add that I have started barnyard2 pointing to the latest snort log file, for example if
|
Hello all,
Like many people, Barnyard2 does not read logs from Snort. But I don't understand why. Some help is welcome.
I use :
I test with only one local rule which is :
I tried with rev: 1; but it's not better.
When I run Snort, I can see the ICMP alerts.
And Barnyard2 is waiting for new data :
But my database is empty
Where
Below my config :
Snort :
Barnyard2 :
Do you see a mistake somewhere?
Thanks in advance.
The text was updated successfully, but these errors were encountered: