Snort mailing list archives
Barnyard not using gen-msg.map
From: Jon P <jon () streamlinedev net>
Date: Wed, 4 May 2016 13:05:33 +0000
m using the ET Community rule set. Pulled pork updates this daily. That seems to be working fine. I did something that is causing my alerts to now be loaded as Snort Alert [1:2101411:12] in BASE. I *think* the issue is with the gen_file and sid_file; but my config looks ok. config classification_file: /etc/snort/classification.config config gen_file: /etc/snort/gen-msg.map config reference_file: /etc/snort/reference.config config sid_file: /etc/snort/sid-msg.map input unified2 output alert_fast: stdout output database: log, mysql, user=snort xxxxxxxxxxxxxxxxxxxxxx Both the *.map files look right and have the text for the alerts im seeing. Is it better practice to use the -S and -G options? Thanks! -jp ------------------------------------------------------------------------------ Find and fix application performance issues faster with Applications Manager Applications Manager provides deep performance insights into multiple tiers of your business applications. It resolves application problems quickly and reduces your MTTR. Get your free trial! https://ad.doubleclick.net/ddm/clk/302982198;130105516;z _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- Barnyard not using gen-msg.map Jon P (May 04)
- Re: Barnyard not using gen-msg.map Y M (May 04)
- Re: Barnyard not using gen-msg.map Jon P (May 04)
- Re: Barnyard not using gen-msg.map Y M (May 04)