Snort - the de facto standard for intrusion detection/prevention
next up previous
Next: 5.2 How do I Up: 5 Getting Fancy Previous: 5 Getting Fancy


5.1 I hear people talking about ``Barnyard''. What's that?

Barnyard is a output system for Snort. Snort creates a special binary output format called ``unified.'' Barnyard reads this file, and then resends the data to a database backend. Unlike the database output plugin, Barnyard is aware of a failure to send the alert to the database, and it stops sending alerts. It is also aware when the database can accept connections again and will start sending the alerts again.