Snort mailing list archives
Re: Problem with using 2 sensors
From: beenph <beenph () gmail com>
Date: Tue, 27 Sep 2011 16:10:34 -0400
On Tue, Sep 27, 2011 at 4:01 PM, JJC <cummingsj () gmail com> wrote:
You will want each instance of snort writing to unique unified2 files.. maybe unifiedeth1 and unifiedeht2 for example, then you will want an instance of barnyard PER instance of snort, pointing at each respective unique unified2 filename pattern... JJC
Or having two different log directory ex: /var/log/instance-eth1/LOG and /var/log/instance-eth2/LOG And obviously have two different barnyard2 process with each a conf and make sure they have different sensor ID / name so you can differentiate them. -elz ------------------------------------------------------------------------------ All the data continuously generated in your IT infrastructure contains a definitive record of customers, application performance, security threats, fraudulent activity and more. Splunk takes this data and makes sense of it. Business sense. IT sense. Common sense. http://p.sf.net/sfu/splunk-d2dcopy1 _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- Problem with using 2 sensors Mike Boeckeler (Sep 27)
- Re: Problem with using 2 sensors JJC (Sep 27)
- Re: Problem with using 2 sensors beenph (Sep 27)
- Re: Problem with using 2 sensors Lay, James (Sep 27)
- Re: Problem with using 2 sensors Joel Esler (Sep 27)
- Re: Problem with using 2 sensors Lay, James (Sep 27)
- Re: Problem with using 2 sensors Joel Esler (Sep 27)
- Re: Problem with using 2 sensors Joel Esler (Sep 27)
- Re: Problem with using 2 sensors JJC (Sep 27)
- Re: Problem with using 2 sensors Castle, Shane (Sep 27)
