Jump to content

Recommended Posts

Posted

The error indicates that Barnyard2 is having an issue with the time stamp on the snort.log file.

Log file name Example: merged.log.1377185664

If there is no time stamp on the d:/winids/log/merged.log file then check  the snort.conf lines below for accuracy.

Original Line(s): # output unified2: filename merged.log, limit 128, nostamp, mpls_event_types, vlan_event_types
Change to: output unified2: filename merged.log, limit 128

Posted

OK, that got me working!

I had: 'output unified2: filename merged.log, limit 128 #, nostamp, mpls_event_types, vlan_event_types' in my snort configuration.

Removing the '#, nostamp, mpls_event_types, vlan_event_types' portion has made everything much happier.

Thanks for your help.

  • 10 months later...
Posted

Hi there,

I just upgraded to Snort 2.9.7.3 and I have this issue.  I followed the recommended fix but it didn't resolve the issue.  Anything else it could be?  I was wondering if perhaps it could be that barnyard2 needs to be rebuilt for 2.9.7.3?

Here's my config...

snort.conf

Posted
On ‎5‎/‎26‎/‎2015 at 8:33 PM, jgreninger said:

Hi there,

I just upgraded to Snort 2.9.7.3 and I have this issue.  I followed the recommended fix but it didn't resolve the issue.  Anything else it could be?  I was wondering if perhaps it could be that barnyard2 needs to be rebuilt for 2.9.7.3?

Here's my config...

snort.conf

 

Not real sure about some of you configurations. It appears you are using an outdated snort.conf file. You will need to retrieve a stock snort.conf and configure. Do not activate the SO rules as they are not compatable with Windows.

Delete all the files in snort/logs prior to restarting.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...