Mon Oct 8 18:28:34 EDT 2012

next topic, revisited:

u2spewfoo snort.log.1349734894 
get_record: (2) Failed to read all of record data.
	Read 14476 of 33555456 bytes


i run snort/barnyard2 this way: should i change?

/usr/local/bin/snort -A fast -c /etc/snort/etc/snort.conf -i eth0 &
/usr/local/bin/barnyard2 -c /etc/snort/etc/barnyard2.conf
-d /var/log/snort -f snort.log -w /var/log/snort/barnyard2.waldo

i used the corrections you provided in last email(s).
snort is logging properly, no errors, just Warnings, i fixed the
whitelist sorta, but does not error out, and 3 ip's were loaded,

i think snort is logging NOT to unified2 format properly, since
u2spewfoo gives that error,which could explain why my DB is not
inputing data to mysql db using schemas/mysql_create. make sense?
advise,,, thanks...

ps Mr. Bates is definitely community thus far ;)
