Snort mailing list archives

Re: Quick Barnyard question...


From: Paul Schmehl <pauls () utdallas edu>
Date: Thu, 11 Aug 2005 21:48:48 -0500

--On August 11, 2005 4:57:57 PM -0400 Jeff Kell <jeff-kell () utc edu> wrote:

Mihai Petre wrote:
Oh.
so sguil is only a mysql output for a dbase with a different schema than
the acid/base.
Right ?

Incompatible schemas?  Or just some more addon tables like ACID/BASE?

Incompatible.  Completely different.

Can BASE report on the resulting Barnyard database?

BASE reads a database built with its schema.  It cannot read a sguild db.

Or do you need two databases <shudder>?

Why shudder? We're running one instance of mysql that has about 10 different dbs in it - two for snort - several for other little things I'm doing for reporting purposes.

Basically, a db is just a schema and some binary files. Mysql can run lots of dbs side by side, each with its own unique schema and purposes.

Paul Schmehl (pauls () utdallas edu)
Adjunct Information Security Officer
University of Texas at Dallas
AVIEN Founding Member
http://www.utdallas.edu/


-------------------------------------------------------
SF.Net email is Sponsored by the Better Software Conference & EXPO
September 19-22, 2005 * San Francisco, CA * Development Lifecycle Practices
Agile & Plan-Driven Development * Managing Projects & Teams * Testing & QA
Security * Process Improvement & Measurement * http://www.sqe.com/bsce5sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: