Snort mailing list archives

Re: problems with using barnyard 2-1.2


From: firnsy <firnsy () securixlive com>
Date: Tue, 30 Mar 2010 22:39:14 +1030

Well the configuration file changed a little between 2-1.6 and 2-1.7 to
align to a more Snort-like syntax. So ensure you always read the
supplied configuration in etc/ to get the latest descriptions.

On Mon, 2010-03-29 at 22:21 -0500, Paul Schmehl wrote:
--On March 30, 2010 12:59:13 PM +1300 Russell Fulton 
<r.fulton () auckland ac nz> wrote:

I've finally got around to tweaking the schema in the snort database and
am now moving to using barnyard 2-1.2  but I am getting these errors in
the syslog:

barnyard: WARNING: No function defined to read header.

and no checkpoint file created ?

Looks like it does not know what data basetype to use.

configured with --with-mysql and mysql given in conf file...

Russell, what OS?


Sounds like a non-unified2 file being read or you have a very recent
unified2 that I haven't come across yet.

Feel free to contact me off-line to work this issue, but please start
with the most recent version as previously suggested.

Regards,

-- 
firnsy
www.securixlive.com

Attachment: signature.asc
Description: This is a digitally signed message part

------------------------------------------------------------------------------
Download Intel&#174; Parallel Studio Eval
Try the new software tools for yourself. Speed compiling, find bugs
proactively, and fine-tune applications for parallel performance.
See why Intel Parallel Studio got high marks during beta.
http://p.sf.net/sfu/intel-sw-dev
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Current thread: