Installing Snort on OpenBSD 5.2:

barnyard 2

Barnyard2 was the most troublesome installation. It’s required for snort, & is a complete sod.

The default configuration file, modified for mysql, fails mysteriously. I wrote my own, and then found a number of strange behaviours because there are some edge cases not mentioned in the documentation. In particular, make sure your archive directory is not the same as your snort directory.

I spent a couple of weeks trying to get it working, and the bloody thing kept dying with another weird error. I finally gave up and spent two days fragging those artificial things that deserve to be fragged, only to log in to the machine two days later to find barnyard2 working.


