firnsy / barnyard2

Barnyard2 is a dedicated spooler for Snort's unified2 binary output format.
GNU General Public License v2.0
344 stars 190 forks source link

Barnyard hangs after PulledPork #210

Open samimb opened 7 years ago

samimb commented 7 years ago

I've been running through the Snort guide to setup Snort, Barnyard2 and PulledPork with a MySQL server.

After running PulledPork to updates my signatures Barnyard chokes. I'm not sure what's going on. I've tried to cleanup /var/log/snort/* and touch a new waldo with right permissions. Barnyard does not look open the file.

This is a new installation but I had a cloned machine sitting with the same configuration for 24 hours. No go.

Mar 14 14:26:34 hostname barnyard2[2755]:
Mar 14 14:26:34 hostname barnyard2[2755]:         --== Initializing Barnyard2 ==--
Mar 14 14:26:34 hostname barnyard2[2755]: Initializing Input Plugins!
Mar 14 14:26:34 hostname barnyard2[2755]: Initializing Output Plugins!
Mar 14 14:26:34 hostname barnyard2[2755]: Parsing config file "/etc/snort/barnyard2.conf"
Mar 14 14:26:34 hostname barnyard2[2755]: #012#012+[ Signature Suppress list ]+#012----------------------------
Mar 14 14:26:34 hostname barnyard2[2755]: +[No entry in Signature Suppress List]+
Mar 14 14:26:34 hostname barnyard2[2755]: ----------------------------#012+[ Signature Suppress list ]+#012
Mar 14 14:27:57 hostname barnyard2[2755]: WARNING: invalid Reference spec '2015-0666'. Ignored
Mar 14 14:28:03 hostname barnyard2[2755]: Barnyard2 spooler: Event cache size set to [2048]
Mar 14 14:28:03 hostname barnyard2[2755]: Log directory = /var/log/barnyard2
Mar 14 14:28:03 hostname barnyard2[2755]: INFO database: Defaulting Reconnect/Transaction Error limit to 10
Mar 14 14:28:03 hostname barnyard2[2755]: INFO database: Defaulting Reconnect sleep time to 5 second
Mar 14 14:28:03 hostname barnyard2[2755]: Initializing daemon mode
Mar 14 14:28:03 hostname barnyard2[2755]: Daemon initialized, signaled parent pid: 1
Mar 14 14:28:03 hostname barnyard2[2755]: PID path stat checked out ok, PID path set to /var/run/
Mar 14 14:28:03 hostname barnyard2[2755]: Writing PID "2755" to file "/var/run//barnyard2_NULL.pid"