Ben's notes

Linux, Unix, network, radio...

User Tools

Site Tools


snort_and_snorby

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
Next revisionBoth sides next revision
snort_and_snorby [2014/05/09 21:42] – [Install and start Snorby] adminsnort_and_snorby [2014/05/09 22:35] admin
Line 109: Line 109:
 Create a sample rules file (eg. look at etc/barnyard2.conf) Create a sample rules file (eg. look at etc/barnyard2.conf)
 barnyard2 -? barnyard2 -?
 +
 +edit /usr/local/etc/barnyard2.conf
 +
 +config reference_file:      /usr/local/snort/etc/reference.config
 +config classification_file: /usr/local/snort/etc/classification.config
 +config gen_file:            /usr/local/snort/etc/gen-msg.map
 +config sid_file:            /usr/local/snort/etc/sid-msg.map
 +config logdir: /mnt/snort/log
 +config hostname:   snort
 +config interface:  eth1
 +config daemon
 +config waldo_file: /mnt/snort/bylog.waldo
 +config archivedir: /mnt/snort/archive
 +input unified2
 +output alert_fast: /mnt/snort/log/barnyard2.alert
 +output database: log, mysql, user=snort password=snortpass dbname=snorby host=snorby
 +
 +
 +ln -s /etc/snort/gen-msg.map /usr/local/snort/etc
 +/usr/local/bin/barnyard2 -c /usr/local/etc/barnyard2.conf -d /mnt/snort/log -f snort_eth1.u2
 </code> </code>
snort_and_snorby.txt · Last modified: 2021/10/09 15:14 by 127.0.0.1