O'Reilly logo

Intrusion Detection with Snort by Jack Koziol

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

Implementing Barnyard

Installing and configuring Barnyard is a relatively straightforward and simple task. Barnyard was designed to have limited but powerful functionality. It is intended to perform only one function, and do it very well: the generation of alerts from Snort intrusion data. Barnyard has no other planned features, with the exception of processing alerts stored in the Snort Unified format.

Barnyard has three basic modes of operation:

  • One-shot

  • Continual

  • Continual with checkpointing

One-shot mode is used to process a Snort unified file in a single run. Barnyard processes the file, generates alerts, and then exits. When Barnyard is set in continual mode, it starts with a file and continuously processes data as it is created by Snort. ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required