Snort mailing list archives

Re: Problem with using 2 sensors


From: beenph <beenph () gmail com>
Date: Tue, 27 Sep 2011 16:10:34 -0400

On Tue, Sep 27, 2011 at 4:01 PM, JJC <cummingsj () gmail com> wrote:
You will want each instance of snort writing to unique unified2 files..
maybe unifiedeth1 and unifiedeht2 for example, then you will want an
instance of barnyard PER instance of snort, pointing at each respective
unique unified2 filename pattern...
JJC


Or having two different log directory ex: /var/log/instance-eth1/LOG
and  /var/log/instance-eth2/LOG
And obviously have two different barnyard2 process with each a conf
and make sure they have different sensor ID / name so you can
differentiate them.


-elz

------------------------------------------------------------------------------
All the data continuously generated in your IT infrastructure contains a
definitive record of customers, application performance, security
threats, fraudulent activity and more. Splunk takes this data and makes
sense of it. Business sense. IT sense. Common sense.
http://p.sf.net/sfu/splunk-d2dcopy1
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: