LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 02-07-2014, 08:26 AM   #1
3rensho
Senior Member
 
Registered: Mar 2008
Location: Deutschland
Distribution: Slackware64-current
Posts: 1,096

Rep: Reputation: 660Reputation: 660Reputation: 660Reputation: 660Reputation: 660Reputation: 660
Snort-2.9.6.0 on Slackware64-current


I had been running Snort-2.9.5.6 and all was fine. Yesterday I upgraded to Snort-2.9.6.0 and Snort runs just fine but a puzzling change has occurred in the output I see from Barnyard. When I ping a host from my machine the barnyard output is normal -

02/07-15:17:13.527633 [**] [1:10000001:1] ICMP test [**] [Classification ID: 0] [Priority ID: 0] {ICMP} 213.188.254.200 -> 192.168.1.205
02/07-15:17:13.527633 [**] [1:477:3] Snort Alert [1:477:3] [**] [Classification ID: 0] [Priority ID: 0] {ICMP} 213.188.254.200 -> 192.168.1.205

However, whenever an event is logged from the outside world all I get is pages of the following -

02/07-14:09:39.811984 [**] [1:477:3] Snort Alert [1:477:3] [**]
02/07-14:09:44.347567 [**] [1:477:3] Snort Alert [1:477:3] [**]
02/07-14:09:44.790938 [**] [1:477:3] Snort Alert [1:477:3] [**]

I have checked all config files many, many times and see nothing amiss. I then upgraded to Barnyard-2.0.2 and that didn't help either. I've got all of the 2.9.6.0 rules loaded as normal in /etc/snort/rules.

Can any Snort/Barnyard guru please point me to something to check out please?? Thanks in advance.
 
Old 02-08-2014, 04:38 AM   #2
3rensho
Senior Member
 
Registered: Mar 2008
Location: Deutschland
Distribution: Slackware64-current
Posts: 1,096

Original Poster
Rep: Reputation: 660Reputation: 660Reputation: 660Reputation: 660Reputation: 660Reputation: 660
DOH!!!! Got it sorted
 
Old 03-03-2014, 05:06 PM   #3
JVijsma
LQ Newbie
 
Registered: Mar 2014
Posts: 1

Rep: Reputation: Disabled
Quote:
Originally Posted by 3rensho View Post
DOH!!!! Got it sorted
So, can you tell me how??
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
upgrading slackware64 13.1 multilib to slackware64 -current multilib Cultist Slackware 4 03-12-2011 09:04 AM
Slackware64-Current from USB? THCsphere Slackware - Installation 1 11-29-2009 03:36 AM
Updating from Slackware64-current to Slackware64 13. glore2002 Slackware 4 08-28-2009 06:50 PM
Slackware64-current on a second HD. glore2002 Slackware 7 08-23-2009 11:38 AM
[SOLVED] what's that directory (slackware64-current) sycamorex Slackware 3 05-30-2009 09:03 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 01:17 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration