[Snort-users] Snort 2.9, barnyard2, and unknown record types
firnsy at ...14568...
Wed Nov 3 03:38:07 EDT 2010
On Tue, 2010-11-02 at 14:10 -0500, Rich Graves wrote:
> I can't keep barnyard2 running on unified2 files generated by snort 126.96.36.199 (64-bit RHEL5). A couple times a day, it chokes on a bad record. This never happened with 2.8.6.
> I got things to "work" for a while by hacking barnyard2-1.9-beta1 to ignore (return 0) record type 110, but now I'm seeing record type 4, which doesn't even appear in sfutil/Unified2_common.h.
> What should I be looking at to figure this out?
> I've reverted production to 2.8.6. Still have a test running 2.9.
> barnyard2: Opened spool file '/var/log/snort/snort-unified2.log.1288720898'
> barnyard2: WARNING: Unhandled UNIFIED2_EXTRA_DATA record type 110
> barnyard2: FATAL ERROR: Unknown record type read: 4
I've only just sat down and started playing with snort 2.9.x so I should
have some updates coming down the line soon.
BTW the project source is finally being hosted publicly over at github.
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 490 bytes
Desc: This is a digitally signed message part
More information about the Snort-users