Baryard2 logging multiple messages at once

  • New to Snort and Barnyard2 here, but I have a question about how it is logging messages. I have a Splunk instance receiving syslog messages from Barnyard2, but I see multiple alerts in each message that Barnyard2 is sending - sometimes up to 100+ alerts. Is this normal? I would rather have it send a separate message for each alert for trending purposes.

    Thanks in advance for the help.

Log in to reply