Issue with SNORT/BARNYARD2/SYSLOG data

Issue with SNORT/BARNYARD2/SYSLOG data

Hi,

I'm trying to get our SNORT logs within Firewall Analyzer, without any success...
I have tried all SYSLOG format available in Barnyard2, but all appear as "Unsupported Logs Received" in FA.

# Barnyard2 Usage Examples:
# output alert_syslog_full: sensor_name snortIds1-eth2, server xxx.xxx.xxx.xxx, protocol udp, port 514, operation_mode default
# output alert_syslog_full: sensor_name snortIds1-eth2, server xxx.xxx.xxx.xxx, protocol udp, port 514, operation_mode complete
# output log_syslog_full: sensor_name snortIds1-eth2, server xxx.xxx.xxx.xxx, protocol udp, port 514, operation_mode default
# output log_syslog_full: sensor_name snortIds1-eth2, server xxx.xxx.xxx.xxx, protocol udp, port 514, operation_mode complete
# output alert_syslog_full: sensor_name snortIds1-eth2, server xxx.xxx.xxx.xxx, protocol udp, port 514
# output log_syslog_full: sensor_name snortIds1-eth2, server xxx.xxx.xxx.xxx, protocol udp, port 514

Can you please let me know which SNORT SYLOG format is actually supported by Firewall Analyzer?

Thanks,
Julien

                New to ADSelfService Plus?