very informative, great post! i’m curious why you decided to use suricata and not snort? how is it working out for you?
ah I never played with suricata before and I wanted to give it a try. It seems to run quite fast (faster than snort, but I may not have been running it long enough to really compare)
this is a great tutorial, i follow it and it works fine. am having difficulties in running snorby under a subdirectoy (rather than have it in the top domain) when i point to the top domain, http://mydomain.com I can see the login screen and everything is working fine ! However, when i point to a subdirectory http://mydomain.com/mysnorby it is not working and giving me the snorby directory listing. I tried to play with the apache virtual host configuration , but no luck.
Update : you can download barnyard2 packages here : https://launchpad.net/~hurricanedefense/+archive/testing/+build/2315749