<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Snort&#x2F;Barnyard2 doesn&#x27;t update events in Snorby after upgrade]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I don't have the exact same error as Greg97, but my problem also happened after I upgraded to the latest version of pfsense last week. Prior to the upgrade everything seemed to work fine. My snort and barnyard2 config was happily filling my mysql database and snorby presented all of it nicely. Now for some reason barnyard does connect to the mysql server but it no longer writes events to it. The unified2 archives are piling up on pfsense and thats it.</p>
<p dir="auto">When I flush the database and restart snorby to generate the tables again everything works fine. Barnyard also starts and starts to fill the database again. Then after a while it just stops. I can restart the service, but then I'm back at the point that barnyard does no longer commit new events to the database.</p>
<p dir="auto">When I restart the barnyard service it connects to the database fires the "SELECT sig_id, sig_sid, sig_gid,sig_rev, sig_class_id, sig_priority, sig_name FROM signature" qeury and form then on its quiet.</p>
<p dir="auto">I've even restored an older snapshot from 2.1.5 of pfsense and upgraded again to 2.2.1, but this makes no difference.</p>
<p dir="auto">I've been trying to figure out why it happens, but I could need some pointers.</p>
<p dir="auto">I'm running:<br />
Snort 2.9.7.2 pkg v3.2.4 on 2.2.1-RELEASE (i386) FreeBSD 10.1-RELEASE-p6<br />
MySQL  5.5.38-0+wheezy1-log (Debian) server on my Netgear NAS<br />
Snorby  rake, version 0.9.2 on Ubuntu 14.04.1 LTS</p>
<p dir="auto">Thanks<br />
Splinter</p>
]]></description><link>https://forum.netgate.com/topic/82420/snort-barnyard2-doesn-t-update-events-in-snorby-after-upgrade</link><generator>RSS for Node</generator><lastBuildDate>Tue, 14 Apr 2026 18:25:08 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/82420.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 06 Apr 2015 20:31:47 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Snort&#x2F;Barnyard2 doesn&#x27;t update events in Snorby after upgrade on Tue, 14 Apr 2015 14:15:11 GMT]]></title><description><![CDATA[<p dir="auto">Yes works like a charm</p>
]]></description><link>https://forum.netgate.com/post/536231</link><guid isPermaLink="true">https://forum.netgate.com/post/536231</guid><dc:creator><![CDATA[splinter]]></dc:creator><pubDate>Tue, 14 Apr 2015 14:15:11 GMT</pubDate></item><item><title><![CDATA[Reply to Snort&#x2F;Barnyard2 doesn&#x27;t update events in Snorby after upgrade on Thu, 09 Apr 2015 00:16:56 GMT]]></title><description><![CDATA[<p dir="auto">Can you click on the DNS reverse resolve icon when looking at an alert and get a reply?  Once I put an IPv6 address on my Snorby server, I lost that ability.  I can't even look up IPv4 addresses from within Snorby.</p>
<p dir="auto">Bill</p>
]]></description><link>https://forum.netgate.com/post/534859</link><guid isPermaLink="true">https://forum.netgate.com/post/534859</guid><dc:creator><![CDATA[bmeeks]]></dc:creator><pubDate>Thu, 09 Apr 2015 00:16:56 GMT</pubDate></item><item><title><![CDATA[Reply to Snort&#x2F;Barnyard2 doesn&#x27;t update events in Snorby after upgrade on Wed, 08 Apr 2015 10:25:33 GMT]]></title><description><![CDATA[<p dir="auto">Oh I got IPv6 working fine on my Snorby box, it can even identify itself with it's hostname to my MySQL server. I consider myself lucky then. Until now Barnyard is doing alright.</p>
]]></description><link>https://forum.netgate.com/post/534677</link><guid isPermaLink="true">https://forum.netgate.com/post/534677</guid><dc:creator><![CDATA[splinter]]></dc:creator><pubDate>Wed, 08 Apr 2015 10:25:33 GMT</pubDate></item><item><title><![CDATA[Reply to Snort&#x2F;Barnyard2 doesn&#x27;t update events in Snorby after upgrade on Wed, 08 Apr 2015 00:02:00 GMT]]></title><description><![CDATA[<p dir="auto">Ah…OK.  I know Barnyard2 is not great with IPv6 support, and Snorby does not really support it at all so far as I know.  On my box, enabling IPv6 broke the DNS lookups from within Snorby (they still work fine from the Ubuntu CLI, so the failure is a Snorby issue).  I looked at the Snorby code and it uses only IPv4 library calls for that.  Also likely means other IPv6 stuff in Snorby is not well supported.</p>
<p dir="auto">Bill</p>
]]></description><link>https://forum.netgate.com/post/534570</link><guid isPermaLink="true">https://forum.netgate.com/post/534570</guid><dc:creator><![CDATA[bmeeks]]></dc:creator><pubDate>Wed, 08 Apr 2015 00:02:00 GMT</pubDate></item><item><title><![CDATA[Reply to Snort&#x2F;Barnyard2 doesn&#x27;t update events in Snorby after upgrade on Tue, 07 Apr 2015 20:07:31 GMT]]></title><description><![CDATA[<p dir="auto">Hey Bill,</p>
<p dir="auto">Somehow this seems to have a lot to do with my network being dualstacked. I reconfigured the barnyard interface to use the ipv4 hostname of my mysql instance. This worked better than the ipv6 connection. Second, there were some entries showing up in Snorby that had unidentifiable ip addresses. When I correlate these to my alerts tab in snort these translate to ipv6 addresses. Although it's only Snorby not displaying the IP addresses correctly, I'm still going to suppress these alerts for now. Let's see if this is a more stable configuration.</p>
<p dir="auto">Hopefully barnyard will hold up this time.</p>
<p dir="auto">cheers<br />
Splinter</p>
]]></description><link>https://forum.netgate.com/post/534508</link><guid isPermaLink="true">https://forum.netgate.com/post/534508</guid><dc:creator><![CDATA[splinter]]></dc:creator><pubDate>Tue, 07 Apr 2015 20:07:31 GMT</pubDate></item><item><title><![CDATA[Reply to Snort&#x2F;Barnyard2 doesn&#x27;t update events in Snorby after upgrade on Tue, 07 Apr 2015 04:26:23 GMT]]></title><description><![CDATA[<p dir="auto">That returns:<br />
9085 rows in set (0.32 sec)</p>
<p dir="auto">:-/</p>
<p dir="auto">Splinter</p>
]]></description><link>https://forum.netgate.com/post/534261</link><guid isPermaLink="true">https://forum.netgate.com/post/534261</guid><dc:creator><![CDATA[splinter]]></dc:creator><pubDate>Tue, 07 Apr 2015 04:26:23 GMT</pubDate></item><item><title><![CDATA[Reply to Snort&#x2F;Barnyard2 doesn&#x27;t update events in Snorby after upgrade on Tue, 07 Apr 2015 01:39:29 GMT]]></title><description><![CDATA[<p dir="auto">What happens if you log in to the MySQL database and execute that same query?  Does it return results?  This seems to be on the MySQL side of things in the DB server.</p>
<p dir="auto">Bill</p>
]]></description><link>https://forum.netgate.com/post/534250</link><guid isPermaLink="true">https://forum.netgate.com/post/534250</guid><dc:creator><![CDATA[bmeeks]]></dc:creator><pubDate>Tue, 07 Apr 2015 01:39:29 GMT</pubDate></item></channel></rss>