Barnyard2 Waiting for new spool file

136 views
Skip to first unread message

Suraj Balvanshi

unread,
Sep 9, 2020, 4:03:31 PM9/9/20
to barnyard2-users

Hello,

I m trying to run snort with barnyard2

i ran into issue when i run the command below:

sudo barnyard2 -c /etc/snort/barnyard2.conf -d /var/log/snort -f snort.u2 -w /var/log/snort/barnyard2.bookmark -g snort -u snort

Error is :

WARNING: Ignoring corrupt/truncated waldofile '/var/log/snort/barnyard2.bookmark'
Waiting for new spool file

barnyard initializes properly, snort is installed properly

running on ubuntu 16.04 LTS desktop

ubuntu@ubuntu:/var/log/snort$ snort -V

   ,,_     -*> Snort! <*-
  o"  )~   Version 2.9.16.1 GRE (Build 140)
   ''''    By Martin Roesch & The Snort Team: http://www.snort.org/contact#team
           Copyright (C) 2014-2020 Cisco and/or its affiliates. All rights reserved.
           Copyright (C) 1998-2013 Sourcefire, Inc., et al.
           Using libpcap version 1.7.4
           Using PCRE version: 8.38 2015-11-23
           Using ZLIB version: 1.2.8


  ______   -*> Barnyard2 <*-
 / ,,_  \  Version 2.1.14 (Build 337)
 |o"  )~|  By Ian Firns (SecurixLive): http://www.securixlive.com/
 + '''' +  (C) Copyright 2008-2013 Ian Firns <fir...@securixlive.com>



Screenshot from 2020-09-09 13-02-56.png

Noah Dietrich

unread,
Sep 10, 2020, 4:09:12 AM9/10/20
to barnyar...@googlegroups.com
you could try deleting your bookmark file, and recreating it (empty). something like:
sudo rm /var/log/snort/barnyard2.bookmark
sudo touch /var/log/snort/barnyard2.bookmark

--

---
You received this message because you are subscribed to the Google Groups "barnyard2-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to barnyard2-use...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/barnyard2-users/f2809c33-1800-4a07-916f-3fd070d37590n%40googlegroups.com.

Suraj Balvanshi

unread,
Sep 10, 2020, 3:15:10 PM9/10/20
to barnyar...@googlegroups.com
thank you after doing that it worked all good
really thank you so much


You received this message because you are subscribed to a topic in the Google Groups "barnyard2-users" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/barnyard2-users/LD2leaHOK1k/unsubscribe.
To unsubscribe from this group and all its topics, send an email to barnyard2-use...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/barnyard2-users/CA%2BN0JExExGgw1yJTLtMaovM230Vrd2H3xgWWcyvf-mji2Dqcmw%40mail.gmail.com.
Reply all
Reply to author
Forward
0 new messages