Snort mailing list archives

Re: Snort Install successful - Need a proper database


From: waldo kitty <wkitty42 () windstream net>
Date: Mon, 19 Nov 2012 16:43:27 -0500

On 11/19/2012 14:38, k vijay sai prashanth wrote:
Hello Team,

Please help me on this. I am close to completing my installation of snort. I can
feel it. Also if someone can tell me the relevance of Barnyard2. Everyone seems
to be discussing about this. How does it help me. Does it help me interpret the
logs of snort?

as discussed in this thread -> Snortsam patch for 2.9.3.1 <- as a thread drift 
instigated by me, barnyard2 takes the output from snort and converts it to 
numerous other output formats so that snort can perform the busy job of sniffing 
the traffic and not having to worry about getting the output to the 
destination... snort writes the files that barnyard2 reads... then barnyard2 
handles getting the data into databases or feeding it to front ends... barnyard2 
can take all the time it needs while snort keeps on snorting and logging without 
slowing down...

      snort -> by2_input_files -> by2 -> database

as for installing a database and creating the tables, install mysql and 
barnyard2... in the barnyard2 installation stuff, there will be something 
describe and possibly even create the tables you will need... from there, you 
can then choose what front end you want to use to peruse the data generated...

personally, i'm this || close to taking the plunge and seeing what i can break 
in the closed environment we use over here ;)

------------------------------------------------------------------------------
Monitor your physical, virtual and cloud infrastructure from a single
web console. Get in-depth insight into apps, servers, databases, vmware,
SAP, cloud infrastructure, etc. Download 30-day Free Trial.
Pricing starts from $795 for 25 servers or applications!
http://p.sf.net/sfu/zoho_dev2dev_nov
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: