0.2.0 fails opening non-alert_unified log files
Status: Beta
Brought to you by:
andrewbaker
Attempting to start 0.2.0 in daemon mode on a log file
created by snort as log_unified or unified (see syslog
messages below) results in the following errors:
Oct 6 13:39:00 leibnitz barnyard[7114]: FATAL ERROR:
ERROR: No input plugin found for magic: a1b2c3d4
Oct 6 13:51:20 leibnitz barnyard[7636]: FATAL ERROR:
ERROR: No input plugin found for magic: 2dac5ceb
Strangely, in batch-mode, I was able to get it to
process the log_unified file (I didn't try with a
'unified' log). Version 0.1.0 used to be able to do this.
--
Jim Clausing (clausing@ieee.org)