[Snort-users] Barnyard2 and multiple sensors

Mike Lococo mikelococo at ...11827...
Sun Oct 31 19:57:26 EDT 2010


> So if you are splitting traffic on a single interface between two
> snort instances how do we configure barnyard2 so that it does not
> trip over itself with respect to sids.

I don't follow your description here.  When I think of a sid I think of
the number that uniquely identifies a snort rule in a rulefile.  I'm not
sure how barnyard could "trip over" that identifier.  What exactly are
you trying to achieve, how did you configure the behavior with your
previous tools, and what's misbehavior that you're observing now with

> From the source I think barnyard is supposed to take a filter on
> the commandline and us it to select sid but it still writes the pid
> file as barnyard2_<int>.pid so this will fail ???

I'm not following the failure-mode here, either.  What did you expect to
happen and what did you observe instead?

Mike Lococo

