Snort mailing list archives
Barnyard vs. Mudpit
From: <jonasb () alum rpi edu>
Date: Wed, 21 Apr 2004 07:38:02 -0700
Hi All - I've been reading through the list archives to learn more about my output options, but haven't found a definitive answer yet. I've set up Barnyard to output to a remote mysql server from my Snort sensor. Everything works fine, although I am a bit concerned about the duplicate entry issue w/ alert rules. So, I figured, why not try mudpit. I've read however that some people weren't really able to capture sessions using stream processing and tag rules. I'd like to be able to have that functionality - has anyone been able to get this to work with Mudpit? If not, can you think of any other options? Also - on my db server, I'm running syslog with swatch on the back-end and would like close to RT email alerting functionality for alerts. I know that Barnyard can output to syslog, but what output Mudpit - if so which output pluging would I use? Thanks! B
Current thread:
- Barnyard vs. Mudpit jonasb (Apr 21)
- <Possible follow-ups>
- RE: Barnyard vs. Mudpit Truax, Shawn (MBS) (Apr 22)
