Snort mailing list archives

Barnyard not using gen-msg.map


From: Jon P <jon () streamlinedev net>
Date: Wed, 4 May 2016 13:05:33 +0000

m using the ET Community rule set. Pulled pork updates this daily. That
seems to be working fine. 

I did something that is causing my alerts to now be loaded as Snort
Alert [1:2101411:12] in BASE. 

I *think* the issue is with the gen_file and sid_file; but my config
looks ok. 

config classification_file: /etc/snort/classification.config
config gen_file:            /etc/snort/gen-msg.map
config reference_file:      /etc/snort/reference.config
config sid_file:            /etc/snort/sid-msg.map
input unified2
output alert_fast: stdout
output database: log, mysql, user=snort xxxxxxxxxxxxxxxxxxxxxx


Both the *.map files look right and have the text for the alerts im
seeing. 

Is it better practice to use the -S and -G options?


Thanks!

-jp

------------------------------------------------------------------------------
Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: