"output log_syslog_full: sensor_name $fakesensorname, server $1.1.1.1, protocol udp, port 514, operation_mode complete"
but I am not receiving anything in my SIEM, please can anyone who has got this operational please advise? or suggest troubleshooting steps (SIEM is confirmed functional when receiving on UDP:514).
Any help would be appreciated.
/CB
* stopping: barnyard2 (spooler, unified2 format) (not running) [ WARN ]
- stale PID file found, deleting!
* starting: barnyard2 (spooler, unified2 format)
My barnyard2.conf file is:
barnyard2.conf: auto-generated by NSMnow Administration on Sun Oct 5 20:25:32 UTC 2014
config logdir: /nsm/sensor_data/Sensorname
config classification_file: /etc/nsm/Sensorname/classification.config
config reference_file: /etc/nsm/Sensorname/reference.config
config sid_file: /etc/nsm/Sensorname/sid-msg.map
config gen_file: /etc/nsm/Sensorname/gen-msg.map
config hostname: Sensorname
config interface: eth1
input unified2
output sguil: sensor_name=Sensorname agent_port=8000
output database: alert, mysql, user=root dbname=snorby host=127.0.0.1 disable_signature_reference_table
#output alert_syslog: LOG_LOCAL6 LOG_ALERT
output log_syslog_full: sensor_name=$Sensorname, server=$1.1.1.1, protocol udp, port 514, operation_mode complete
when i restart barnyard and check the barnyard2.log i see the following:
Executing: barnyard2 -c /etc/nsm/Sensorname/barnyard2.conf -d /nsm/sensor_data/Sensorname -f snort.unified2 -w /etc/nsm/Sensorname/ba rnyard2.waldo -i 1 -U
Running in Continuous mode
--== Initializing Barnyard2 ==--
Initializing Input Plugins!
Initializing Output Plugins!
Parsing config file "/etc/nsm/Sensorname/barnyard2.conf"
: Duplicate classification "default-login-attempt"found, ignoring this line
: Duplicate classification "non-standard-protocol"found, ignoring this line
: Duplicate classification "shellcode-detect"found, ignoring this line
: Duplicate classification "string-detect"found, ignoring this line
: Duplicate classification "suspicious-filename-detect"found, ignoring this line
: Duplicate classification "suspicious-login"found, ignoring this line
: Duplicate classification "system-call-detect"found, ignoring this line
: Duplicate classification "tcp-connection"found, ignoring this line
: Duplicate classification "trojan-activity"found, ignoring this line
: Duplicate classification "unusual-client-port-connection"found, ignoring this line
: Duplicate classification "web-application-activity"found, ignoring this line
ERROR: /etc/nsm/Sensorname/barnyard2.conf(13) Undefined variable name: Sen.
Fatal Error, Quitting..
Barnyard2 exiting
===============================================================================
Record Totals:
Restart Barnyard:
sudo nsm_sensor_ps-restart --only-barnyard2
Restarting: Sensorname
* stopping: barnyard2 (spooler, unified2 format) [ OK ]
* starting: barnyard2 (spooler, unified2 format) [ OK ]
LOG FILE:
tail -300 /var/log/nsm/Sensorname/barnyard2.log
Executing: barnyard2 -c /etc/nsm/Sensorname/barnyard2.conf -d /nsm/sensor_data/Sensorname -f snort.unified2 -w /etc/nsm/Sensorname/ba rnyard2.waldo -i 1 -U
Running in Continuous mode
--== Initializing Barnyard2 ==--
Initializing Input Plugins!
Initializing Output Plugins!
Parsing config file "/etc/nsm/Sensorname/barnyard2.conf"
: Duplicate classification "default-login-attempt"found, ignoring this line
: Duplicate classification "non-standard-protocol"found, ignoring this line
: Duplicate classification "shellcode-detect"found, ignoring this line
: Duplicate classification "string-detect"found, ignoring this line
: Duplicate classification "suspicious-filename-detect"found, ignoring this line
: Duplicate classification "suspicious-login"found, ignoring this line
: Duplicate classification "system-call-detect"found, ignoring this line
: Duplicate classification "tcp-connection"found, ignoring this line
: Duplicate classification "trojan-activity"found, ignoring this line
: Duplicate classification "unusual-client-port-connection"found, ignoring this line
: Duplicate classification "web-application-activity"found, ignoring this line
+[ Signature Suppress list ]+
----------------------------
+[No entry in Signature Suppress List]+
----------------------------
+[ Signature Suppress list ]+
WARNING: Ignoring bad line in SID file: 'v1'
You received this message because you are subscribed to a topic in the Google Groups "security-onion" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/security-onion/Ixgnl0IUsd4/unsubscribe.
To unsubscribe from this group and all its topics, send an email to security-onio...@googlegroups.com.
Is there any other method of sending the full alert and packet data to an external SIEM?
/CB
The other method of sending the full alert and packet data is "output database"
@Jose: I am very interested in the "output database" option but cant find any information on its usage or how to configure it, do you have experience with this?
/CB
--
You received this message because you are subscribed to a topic in the Google Groups "security-onion" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/security-onion/Ixgnl0IUsd4/unsubscribe.
To unsubscribe from this group and all its topics, send an email to security-onio...@googlegroups.com.