OK I ran your script and made the custon barnyard.conf file but I still ran into errors and a few questions. Here's the output of the script working on two log files.
-*> Barnyard! <*-
Version 0.1.0-rc3 (Build 11)
By Andrew R. Baker (andrewb@snort.org)
and Martin Roesch (roesch@sourcefire.com,
www.snort.org)
Loading Data Processors...
dp_alert loaded
dp_log loaded
dp_stream_stat loaded
Loading Built-in Output Plugins...
Fast Alert plugin initialized
AlertSyslog initialized
Log Dump plugin initialized
LogPcap initialized
AlertCSV initialized
Parsing Config file: /etc/snort/barnyard.conf
WARNING: absolute path in -f <filename> is overriding -d <spool_dir> setting.
WARNING: spool_dir set to "/tmp/snort/"
Barnyard Version 0.1.0-rc3 (Build 11) started
ERROR => No input plugin found for magic: 5d2a2a5b
Fatal Error, Quitting..
Exiting
-*> Barnyard! <*-
Version 0.1.0-rc3 (Build 11)
By Andrew R. Baker (andrewb@snort.org)
and Martin Roesch (roesch@sourcefire.com,
www.snort.org)
Loading Data Processors...
dp_alert loaded
dp_log loaded
dp_stream_stat loaded
Loading Built-in Output Plugins...
Fast Alert plugin initialized
AlertSyslog initialized
Log Dump plugin initialized
LogPcap initialized
AlertCSV initialized
Parsing Config file: /etc/snort/barnyard.conf
WARNING: absolute path in -f <filename> is overriding -d <spool_dir> setting.
WARNING: spool_dir set to "/tmp/snort/"
Barnyard Version 0.1.0-rc3 (Build 11) started
ERROR => No input plugin found for magic: 322f3031
Fatal Error, Quitting..
Exiting
In the barnyard.cnf fiel you haev a line that says: output_alert csv
What does that do? If its a parsed file output where does it end up?
Nice script by the way.
--tarballedtux