Snort Base Barnyard and CIDs
Status: Beta
Brought to you by:
andrewbaker
Guys,
I am having a slight problem with the way I want
to use base, snort and barnyard. As alerts come in
the are examined, investigated etc, and then archived
to an archive database. This keeps the live alert
database lean and mean! Unfortunately barnyard looks
at the live alert database to determine the next CID
to use, thus if all of the alerts have been dealt
with from a particular sensor then the CID is set
back to 1 for the next new alert. If I try to archive
the new alert I get an error saying that it is a
duplicate alert and it has been ignored. is there any
way to get barnyard to look at both databses and pick
the highest CID?