Next: 6.2 How do I
Up: 6 Getting Fancy
Previous: 6 Getting Fancy
6.1 I hear people talking about ``Barnyard''. What's that?
Barnyard is a output system for Snort. Snort creates a special binary output
format called ``unified.'' Barnyard reads this file, and then resends the data
to a database backend. Unlike the database output plugin, Barnyard is aware of
a failure to send the alert to the database, and it stops sending alerts. It is
also aware when the database can accept connections again and will start
sending the alerts again.
Nigel Houghton
2006-10-02
|