Snort mailing list archives

Re: barnyard2: WARNING: Can't extract timestamp extension from 'merged.log'using base ''


From: Xander <reg.regedit () gmail com>
Date: Fri, 31 Jul 2015 08:45:05 +0200

By default, a timestamp is appended at the end of the log files. Like
this: snort_merged.log.XXXXXXXXXX.

However, if you use the 'nostamp' option in the snort.conf file, the
timestamp will not be appended anymore, and you will get log files
like this: snort_merged.log.

I think the warning you get from BASE is because of the missing
timestamp at the end of the filename, so try to remove the 'nostamp'
option.

If you still get the warning and you are not using the 'nostamp'
option, maybe you have some old log files in snort's log directory
that do not have a timestamp. Try to remove them and see if you get
the warning again.

------------------------------------------------------------------------------
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: