[Snort-users] snort - unified2 formart
michael.mittentag at ...11827...
Wed Jun 11 10:30:46 EDT 2014
I am running the latest version of snort
I added this and commented out the other lines:
output unified2: filename snort.u2, limit 128
if I try to start snort using the /etc/init.d/snortd script it runs it as:
/usr/sbin/snort -A fast -b -d -D -i eth0 -u snort -g snort -c
/etc/snort/snort.conf -l /var/log/snort
and I never see those snort u2 files instead I see:
and barnyard2 seems to have an issue with reading those files.
If i manually run snort form (/usr/sbin/snort -c /etc/snort/snort.conf)
without any options it then creates the right file type
It is almost like it is not reading /etc/snort/snort.conf?
If anyone has any ideas that would be great.
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Snort-users