Re: snort topology doesn't emitted automatically

2017-03-22 Thread tkg_cangkul
sorry but there i didn't found that directory on my cluster. for your information, i'm using metron 0.3.0 now. when i try to run this command manually : tail -F /var/log/snort/alert.csv | /usr/yava/2.2.0.5/kafka/bin/kafka-console-producer.sh --broker-list localhost:6667 --topic snort i've

Re: snort topology doesn't emitted automatically

2017-03-22 Thread Otto Fowler
/opt/snort-producer/start-snort-producer.sh On March 22, 2017 at 13:30:36, tkg_cangkul (yuza.ras...@gmail.com) wrote: start_snort_producer.sh

Re: snort topology doesn't emitted automatically

2017-03-22 Thread tkg_cangkul
where i can find the start_snort_producer.sh script? i didn't see it inside my metron_home dir On 22/03/17 23:54, Otto Fowler wrote: One time, I saw an issue where the flume agent did not have the correct rights to access the csv, so died a horrible death. We don’t use flume any longer

Re: snort topology doesn't emitted automatically

2017-03-22 Thread Otto Fowler
One time, I saw an issue where the flume agent did not have the correct rights to access the csv, so died a horrible death. We don’t use flume any longer however. I would want to take a look at the log files for what is reading the snort csv. I believe the start_snort_producer.sh script is used