Snort mailing list archives

Re: banrnyard2 always look in /var/log/snort


From: "Asad, Hafiz ul" <Hafiz-ul.Asad () city ac uk>
Date: Thu, 9 Mar 2017 11:53:25 +0000

Yes I am. I use the command,


"barnyard2  -c  /etc/snort/barnyard2.cond  -d  /var/log/snort/here  -f  snort.u2  -w  /var/log/snort/barnyard2.waldo -g 
snort -u snort"


Asad

________________________________
From: Al Lewis (allewi) <allewi () cisco com>
Sent: Thursday, March 9, 2017 11:49:16 AM
To: Asad, Hafiz ul; snort-users () lists sourceforge net
Subject: Re: [Snort-users] banrnyard2 always look in /var/log/snort

https://github.com/firnsy/barnyard2


    Continual Processing Options:
-d <dir> Spool files from <dir>




Are you telling barnyard where to look with the ā€œ-dā€ option?







Albert Lewis
ENGINEER.SOFTWARE ENGINEERING
SOURCEfire, Inc. now part of Cisco
Email: allewi () cisco com







On 3/9/17, 5:43 AM, "Asad, Hafiz ul" <Hafiz-ul.Asad () city ac uk> wrote:

Snort Users,


I want barnyard2 to get "snort.u2" files from a directory  "/var/log/snort/here/", but it always look in to 
"/var/log/snort". How can I make it look in to the desired "/var/log/snort/here/" directory?


Regards

Asad


------------------------------------------------------------------------------
Announcing the Oxford Dictionaries API! The API offers world-renowned
dictionary content that is easy and intuitive to access. Sign up for an
account today to start using our lexical data to power your apps and
projects. Get started today and enter our developer competition.
http://sdm.link/oxford
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!
------------------------------------------------------------------------------
Announcing the Oxford Dictionaries API! The API offers world-renowned
dictionary content that is easy and intuitive to access. Sign up for an
account today to start using our lexical data to power your apps and
projects. Get started today and enter our developer competition.
http://sdm.link/oxford
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: