firnsy / barnyard2

Barnyard2 is a dedicated spooler for Snort's unified2 binary output format.
GNU General Public License v2.0
343 stars 189 forks source link

Snort cannot output the snort.u2.XXXXXXXXXX #216

Open SnakeYPH opened 7 years ago

SnakeYPH commented 7 years ago

Hi there, I have trouble with try to output the snort unified as snoert.u2.xxxxxxxxxx. When I set the snort output as output alert_unified2: filename snort.u2, limit 128 output alert_fast: alert.log, limit 128, nostamp snort will only generate a snort.log.xxxxxxxxxx and alert. I have comment those ALERTMODE and BINARY_LOG the /etc/sysconfig/snort already and it still only generate snort.log.xxxxxxxxxx and alert only. What is wrong and how can I fix this? Thanks!