Snort mailing list archives

Undeliverable:Re: barnyard (fwd)


From: Paul Schmehl <pauls () utdallas edu>
Date: Fri, 27 Jan 2006 23:09:38 -0600

This address has been bouncing for well over a year. Do the administrators of this list think it might be possible to purge the address from the list?

------------ Forwarded Message ------------
Date: January 27, 2006 10:49:02 PM -0600
From: System Administrator <postmaster () utdevs08 utdallas edu>
To: "Schmehl, Paul L" <pauls () utdallas edu>
Subject: Undeliverable:Re: [Snort-users] barnyard

Your message

 To:      Brian Krusic; snort-users () lists sourceforge net
 Subject: Re: [Snort-users] barnyard
 Sent:    Fri, 27 Jan 2006 22:21:16 -0600

did not reach the following recipient(s):

anjah () imedia fr on Fri, 27 Jan 2006 22:26:51 -0600
   The e-mail account does not exist at the organization this message
was sent to.  Check the e-mail address, or contact the recipient
directly to find out the correct address.
   <imedia-hvj182q6.imedia.net #5.1.1>

---------- End Forwarded Message ----------



Paul Schmehl (pauls () utdallas edu)
Adjunct Information Security Officer
University of Texas at Dallas
AVIEN Founding Member
http://www.utdallas.edu/
--- Begin Message --- From: "System Administrator" <postmaster () utdevs08 utdallas edu>
Date: Fri, 27 Jan 2006 22:49:02 -0600
Your message

  To:      Brian Krusic; snort-users () lists sourceforge net
  Subject: Re: [Snort-users] barnyard
  Sent:    Fri, 27 Jan 2006 22:21:16 -0600

did not reach the following recipient(s):

anjah () imedia fr on Fri, 27 Jan 2006 22:26:51 -0600
    The e-mail account does not exist at the organization this message
was sent to.  Check the e-mail address, or contact the recipient
directly to find out the correct address.
    <imedia-hvj182q6.imedia.net #5.1.1>
Reporting-MTA: dns; UTDEVS08.campus.ad.utdallas.edu

Final-Recipient: RFC822; anjah@imedia.fr
Action: failed
Status: 5.1.1
X-Supplementary-Info: <imedia-hvj182q6.imedia.net #5.1.1>
X-Display-Name: anjah@imedia.fr
--- Begin Message --- From: "Schmehl, Paul L" <pauls () utdallas edu>
Date: Fri, 27 Jan 2006 22:21:16 -0600
--On January 27, 2006 4:47:14 PM -0800 Brian Krusic <brian () krusic com> 
wrote:

My command line;

barnard -c /usr/local/barnyard/etc/barnyard.conf -d /var/log/snort -g
/usr/local/snort/etc/gen-msg.map -s /usr/local/snort/etc/sid-msg.map -f
snort.alert

You can run barnyard with this:
barnyard -c /path/to/conffile -d /path/to/logdir -f logfilename

If you do this in the barnyard.conf file
config sid-msg-map: /path/to/sid-msg.map
config gen-msg=map: /path/to/gen-msg.map
config class-file: /path/to/classification.config

This is not in the docs, but it is in the source code.  (I'm the FreeBSD 
port maintainer for barnyard.)

Barnyard can output directly to a text file, to a pcap file, to a database 
(mysql or postgresql) or to sguil.

Paul Schmehl (pauls () utdallas edu)
Adjunct Information Security Officer
University of Texas at Dallas
AVIEN Founding Member
http://www.utdallas.edu/


-------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc. Do you grep through log files
for problems?  Stop!  Download the new AJAX search engine that makes
searching your log files as easy as surfing the  web.  DOWNLOAD SPLUNK!
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=103432&bid=230486&dat=121642
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


--- End Message ---

--- End Message ---

Current thread: