<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Snort &gt; Barnyard2 &gt;syslog fatal error]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">I have Snort package running for very long time, since the last update package to ver 3.2.9.6_1  I have a fatal error as shown below, I tried to delete/recreate  Snort interface, it works for few min/sec and then stops.<br />
Any idea what causing the issue , please advice<br />
Thanks</p>
<p dir="auto">–---event from log</p>
<blockquote>
<p dir="auto">Mar 6 10:50:05 barnyard2 57137 Barnyard2 exiting<br />
Mar 6 10:50:05 barnyard2 57137 FATAL ERROR: [Syslog_FormatIPHeaderLog()], strlcpy() error , bailing<br />
Mar 6 10:50:05 barnyard2 57137 OpSyslog_Log(): Is currently unable to handle Event Type [72]<br />
Mar 6 10:50:05 barnyard2 57137 Opened spool file '/var/log/snort/snort_igb15944/snort_5944_igb1.u2.1519272335'<br />
Mar 6 10:50:05 barnyard2 57137 Using waldo file '/var/log/snort/snort_igb15944/barnyard2/5944_igb1.waldo': spool directory = /var/log/snort/snort_igb15944 spool filebase = snort_5944_igb1.u2 time_stamp = 1519272335 record_idx = 21</p>
</blockquote>
<p dir="auto"><img src="/public/_imported_attachments_/1/pfbarnyard2.png" alt="pfbarnyard2.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/pfbarnyard2.png_thumb" alt="pfbarnyard2.png_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/topic/127811/snort-barnyard2-syslog-fatal-error</link><generator>RSS for Node</generator><lastBuildDate>Fri, 10 Apr 2026 23:20:50 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/127811.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 06 Mar 2018 09:42:21 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Snort &gt; Barnyard2 &gt;syslog fatal error on Wed, 07 Mar 2018 01:35:51 GMT]]></title><description><![CDATA[<p dir="auto">The problem appears to be within Barnyard2.  Notice that is where the error is generated according to the log message.  Barnyard2 on FreeBSD (and thus on pfSense as well) is very old and not well supported.  It will be removed from the Suricata package in the near future, and I'm considering doing the same for Snort because Barnyard2 is so unreliable.</p>
<p dir="auto">Your particular error message comes from Barnyard2 not being able to adequately handle IPv6 events.  Here is a thread link to an open bug report on Github for this issue.  Notice the date is 2015 and still no action, so that's what I mean by Barnyard2 being poorly supported.</p>
<p dir="auto"><a href="https://github.com/firnsy/barnyard2/issues/144" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/firnsy/barnyard2/issues/144</a></p>
<p dir="auto">Bill</p>
]]></description><link>https://forum.netgate.com/post/754082</link><guid isPermaLink="true">https://forum.netgate.com/post/754082</guid><dc:creator><![CDATA[bmeeks]]></dc:creator><pubDate>Wed, 07 Mar 2018 01:35:51 GMT</pubDate></item></channel></rss>