-
as seen on Server Fault
- Search for 'Server Fault'
My site seems to be the target of quite a bit of probing over the last few months. In an attempt to get a better handle on this I installed SNORT on one of the machines that has external exposure. Something must not be installed correctly as I see lots of probing in /var/log/messages but snort isn't…
>>> More
-
as seen on Server Fault
- Search for 'Server Fault'
I need some help with my Snort/Barnyard2 setup. My goal is to have Snort send unified2 logs to Barnyard2 and then have Barnyard2 send the data to other locations. Here is my currrent setup.
OS
Scientific Linux 6
Snort Version
2.9.2.3
Barnyard2 Version
2.1.9
Snort command
snort -c /etc/snort/snort…
>>> More
-
as seen on Server Fault
- Search for 'Server Fault'
I'm trying to identify trouble users on our network. ntop identifies high traffic and high connection users, but malware doesn't always need high bandwidth to really mess things up. So I am trying to do offline analysis with snort (don't want to burden the router with inline analysis of 20 Mbps…
>>> More
-
as seen on Stack Overflow
- Search for 'Stack Overflow'
Hi.
I’m working on DARPA 1998 intrusion detection dataset.
When I run snort on this dataset (outside.tcpdump file), snort don’t generate complete list of alerts. It means snort start from last few hours of tcpdump file and generate alerts about this section of file and all of packets in first hours…
>>> More
-
as seen on Super User
- Search for 'Super User'
I'm trying to learn network intrusion detection. When I try to launch Snort, in IDS mode, I get this message (I'm running Mac OS X):
Initializing Network Interface en1
ERROR: OpenPcap() FSM compilation failed:
syntax error
PCAP command: snort
Fatal Error, Quitting..
How can I fix this problem…
>>> More