Barnyard2 on 1.2.3-RELEASE not working
seraphyn last edited by
I've installed pfSense 1.2.3 with snort package Version 126.96.36.199 pkg v. 1.35 and use banyard2 for sending logs to snorby at my server.
But snort and banyard2 doesn't seems to work.
I mean snort works indeed but banyard2 not
Banyard2 tell me in my system logs:
Mar 29 18:18:03 barnyard2: Waiting for new spool file Mar 29 18:18:03 barnyard2: Waiting for new spool file Mar 29 18:18:03 barnyard2: WARNING: Ignoring corrupt/truncated waldofile '/var/log/snort/barnyard2/6619_xl0.waldo' Mar 29 18:18:03 barnyard2: WARNING: Ignoring corrupt/truncated waldofile '/var/log/snort/barnyard2/6619_xl0.waldo'
Connecting to remote-mysql works like a charm and there is no error in my Syslog.
Only that banyard2 wating for the new spool file.
So banyard2 reports no error to mySQL.
Tested with some scans but nothing was written.
Is there a Fix for it.
I saw a topic from last year that someone mentioned it….
[MODIFIED] I try the RC1 from Version 2 and will have a look if it's workin there [MODIFIED]