[Snort-users] Barnyard

Jason Brvenik jasonb at ...1935...
Fri Nov 9 19:21:46 EST 2007


or you can use SnortUnified.pm, the code in SVN has preliminary support
for unified2 files.

If anyone wants to share some unified2 files with me, and more
specifically, unified2 files with events generated on IPV6 networks, I
would be appreciative.

http://www.snort.org/users/jbrvenik

The first post has the relevant bits.

Jeff Dell wrote:
> Authors are Andrew and Marty.. why don't they change it. :) it would suck to
> have to re-write something that has been stable for 3 years to add support
> for unified2 and ipv6.
> 
> Cheers,
> Jeff
> 
> -----Original Message-----
> From: snort-users-bounces at lists.sourceforge.net
> [mailto:snort-users-bounces at lists.sourceforge.net] On Behalf Of
> randy at ...13561...
> Sent: Friday, November 09, 2007 4:41 PM
> To: joel.esler at ...1935...
> Cc: snort-users at lists.sourceforge.net
> Subject: Re: [Snort-users] Barnyard
> 
>>> <SNIP>
>>>> 2)  Don't have Snort writing directly to DB.  Please look into  
>>>> Barnyard.
>>>>
>>>> Joel
>>> Who is maintaining Barnyard? Is it abandonware now?
>>>
>>> I've been tempted to start working on it myself, but I'm not sure if  
>>> there is any effort already in place that hasn't been openly  
>>> discussed yet.
>>>
>>> Ideas? Comments?
>> No, it's not abandonware.  There has been no need to update it because  
>> the db schema, unified schema, and all others haven't changed in years.
>>
>> There are some licensing issues with Barnyard.  It is not GPL.
>>
> 
> My wish is for Oracle and DB2 support. As far as I can tell, that isn't
> possible with 2.0. 
> 
> I didn't realize it wasn't GPL. How unfortunate.
> 
> -------------------------------------------------------------------------
> This SF.net email is sponsored by: Splunk Inc.
> Still grepping through log files to find problems?  Stop.
> Now Search log events and configuration files using AJAX and a browser.
> Download your FREE copy of Splunk now >> http://get.splunk.com/
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users
> 
> 
> -------------------------------------------------------------------------
> This SF.net email is sponsored by: Splunk Inc.
> Still grepping through log files to find problems?  Stop.
> Now Search log events and configuration files using AJAX and a browser.
> Download your FREE copy of Splunk now >> http://get.splunk.com/
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users
> 




More information about the Snort-users mailing list