Open 9thplayer opened 4 years ago
Much as I hate to send people elsewhere, this project has been pretty quiet for quite a while now. Since you're doing Suricata -> ELK, you might consider filebeat instead, the non-free-licensed version has a Suricata module.
Hey Guys,
I am using barnyard2 on suricata over pfsense firewall. I have enabled barnyard2 to send logs to syslog which is my ELK. Everything works fine but barnyard2 gets stopped after some time and when i open log file it says below error:
============================================
============================================
So work aroung is I delete below file everytime and restart the suricata and barnyard2 starts fine. /var/log/suricata/suricata_bge140240/unified2.alert.1565307024 And that's frustrating. I am not a developer but i tried to find out my way as I was not getting anything on internet so i pulled source code and looked through all the way to this :
case 228: /Defined in some bpf implementation as DLT_IPV4: / case 229: / Defined in some bpf implementation as DLT_IPV6 /
================================== Do i need libpcap new version or something or i can simply disable something in suricata or barnyard2 to get this working properly.
Please help me guys.