[Snort-users] Quick Barnyard question...

Paul Schmehl pauls at ...6838...
Thu Aug 11 19:50:36 EDT 2005


--On August 11, 2005 4:57:57 PM -0400 Jeff Kell <jeff-kell at ...6282...> wrote:

> Mihai Petre wrote:
>> Oh.
>> so sguil is only a mysql output for a dbase with a different schema than
>> the acid/base.
>> Right ?
>
> Incompatible schemas?  Or just some more addon tables like ACID/BASE?
>
Incompatible.  Completely different.

> Can BASE report on the resulting Barnyard database?
>
BASE reads a database built with its schema.  It cannot read a sguild db.

> Or do you need two databases <shudder>?
>
Why shudder?  We're running one instance of mysql that has about 10 
different dbs in it - two for snort - several for other little things I'm 
doing for reporting purposes.

Basically, a db is just a schema and some binary files.  Mysql can run lots 
of dbs side by side, each with its own unique schema and purposes.

Paul Schmehl (pauls at ...6838...)
Adjunct Information Security Officer
University of Texas at Dallas
AVIEN Founding Member
http://www.utdallas.edu/




More information about the Snort-users mailing list