firnsy / barnyard2

Barnyard2 is a dedicated spooler for Snort's unified2 binary output format.
GNU General Public License v2.0
344 stars 190 forks source link

Barnyard2-2.1.14 not writing to Snorby DB #228

Open spnaa84 opened 7 years ago

spnaa84 commented 7 years ago

Hi,

I have around 10 sensors connected to Snorby server. Which has been running find quite sometime, however for the past couple of weeks have been noticing that barnyard takes 2-3 hrs to complete initialization. We have already used disable_signature_reference_table on all sensors barnyard2.conf file. The load on these sensors until initialization complete is anything between 97 -100%. Already truncated the sig_reference and reference table in Snorby.

Any assistance in investigation is appreciated.