Skip to content
This repository has been archived by the owner on Jan 18, 2024. It is now read-only.

barnyard2 u2 alert_fast using GRE IP, not encapsulated IP. #258

Open
brianp9906 opened this issue Jun 23, 2020 · 0 comments
Open

barnyard2 u2 alert_fast using GRE IP, not encapsulated IP. #258

brianp9906 opened this issue Jun 23, 2020 · 0 comments

Comments

@brianp9906
Copy link

Hello,
I'm running Snort 2.9.16 and using "output unified2: filename snort.u2, limit 128". When I use "u2spewfoo" I can see the encapsulated source/dest IP information, but when barnyard writes it to snort-alert.log using "output alert_fast: snort-alert.log" I'm only getting the GRE source IP information. What am I missing?

BTW, I did compile barnyard2 with "./configure --enable-gre"

Thank you

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant