I am new to Snort/Barnyard2/Snorby environment. I implemented the system on Centos 7 with Snort 2.9.9.0, Barnyard 2.1.14 (Build 337) and Snorby 2.6.3. My snort config has two files snort.u2 and alerts.u2
I want them both to go to Snorby - at the moment Barnyard2 is seeing only snort.u2 file if I change to alerts.u2 it is not sending anything to MYSQL.
Also a question: Snorby is only showing stream5: TCP Small Segment Threshold Exceeded - have pages and pages of this error and nothing else - any help with both issues?
Hello,
I am new to Snort/Barnyard2/Snorby environment. I implemented the system on Centos 7 with Snort 2.9.9.0, Barnyard 2.1.14 (Build 337) and Snorby 2.6.3. My snort config has two files snort.u2 and alerts.u2
I want them both to go to Snorby - at the moment Barnyard2 is seeing only snort.u2 file if I change to alerts.u2 it is not sending anything to MYSQL.
Also a question: Snorby is only showing stream5: TCP Small Segment Threshold Exceeded - have pages and pages of this error and nothing else - any help with both issues?