{"id":5080,"date":"2014-05-13T02:19:19","date_gmt":"2014-05-12T17:19:19","guid":{"rendered":"https:\/\/mimumimu.net\/blog\/?p=5080"},"modified":"2014-09-15T13:59:17","modified_gmt":"2014-09-15T04:59:17","slug":"centos-6-5-%e3%81%ab-snorby-%e3%81%a8-suricata-%e3%82%92%e3%82%a4%e3%83%b3%e3%82%b9%e3%83%88%e3%83%bc%e3%83%ab","status":"publish","type":"post","link":"https:\/\/mimumimu.net\/blog\/2014\/05\/13\/centos-6-5-%e3%81%ab-snorby-%e3%81%a8-suricata-%e3%82%92%e3%82%a4%e3%83%b3%e3%82%b9%e3%83%88%e3%83%bc%e3%83%ab\/","title":{"rendered":"CentOS 6.5 \u306b Snorby \u3068 Suricata \u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/upload.wikimedia.org\/wikipedia\/commons\/thumb\/e\/e4\/Suricata_suricatta_-_meerkat_-_suracte_-_Erdm%C3%A4nnchen_07.jpg\/800px-Suricata_suricatta_-_meerkat_-_suracte_-_Erdm%C3%A4nnchen_07.jpg\" width=\"198\" height=\"264\" \/> \u3069\u3046\u3082\u307f\u3080\u3089\u3067\u3059\u3002<\/p>\n<p>IDS \u3068\u3044\u3046\u3068 Snort \u3068\u3044\u3046\u30a4\u30e1\u30fc\u30b8\u3082\u591a\u3044\u304b\u3068\u601d\u3044\u307e\u3059\u304c\u3001    <br \/>\u3075\u3068 Google \u306a\u30da\u30fc\u30b8\u3092\u3055\u307e\u3088\u3063\u3066\u3044\u305f\u3089 Suricata \u3068\u3044\u3046\u3082\u306e\u3092\u898b\u3064\u3051\u307e\u3057\u305f\u306e\u3067\u3001     <br \/>\u3053\u308c\u3092\u5165\u308c\u3066\u307f\u3088\u3046\u304b\u3068\u3002<\/p>\n<p>\u74b0\u5883\u3068\u3057\u3066\u306f CentOS 6.5 \u3067 Hyper-V \u74b0\u5883\u3002    <br \/>Windows Server 2012 (Windows 8) \u4ee5\u964d\u306e Hyper-V \u3067\u3042\u308c\u3070\u30dd\u30fc\u30c8\u30df\u30e9\u30fc\u30ea\u30f3\u30b0\u304c\u4f7f\u3048\u307e\u3059\u306e\u3067     <br \/>\u305d\u306e\u8fba\u3092\u4f7f\u3044\u3064\u3064\u3002<\/p>\n<p>\u4eca\u56de\u306e\u74b0\u5883\u3067\u306f eth0 \u3092\u30df\u30e9\u30fc\u30dd\u30fc\u30c8\u304b\u3089\u306e\u30c7\u30fc\u30bf\u53d7\u3051\u4ed8\u3051\u7528\u306b    <br \/>eth1 \u3092\u7ba1\u7406\u7528\u306b\u69cb\u7bc9\u3057\u3066\u307f\u307e\u3059\u3002<\/p>\n<p>\u53c2\u8003\u306b\u3057\u305f\u3068\u3053\u308d\uff1a<\/p>\n<blockquote>\n<p><a title=\"http:\/\/n40lab.wordpress.com\/2013\/06\/02\/snorby-in-centos-6-4\/\" href=\"http:\/\/n40lab.wordpress.com\/2013\/06\/02\/snorby-in-centos-6-4\/\">http:\/\/n40lab.wordpress.com\/2013\/06\/02\/snorby-in-centos-6-4\/<\/a>       <br \/><a title=\"2013. I&#39;ve tested the installation steps with CentOS 6.4. It also works with CentOS 6.3 Today I&#39;\" href=\"http:\/\/n40lab.wordpress.com\/2013\/05\/31\/installing-suricata-ids-from-source-centos-6-3\/\">http:\/\/n40lab.wordpress.com\/2013\/05\/31\/installing-suricata-ids-from-source-centos-6-3\/<\/a>       <br \/><a title=\"https:\/\/redmine.openinfosecfoundation.org\/projects\/suricata\/wiki\/Suricata_Snorby_and_Barnyard2_set_up_guide\" href=\"https:\/\/redmine.openinfosecfoundation.org\/projects\/suricata\/wiki\/Suricata_Snorby_and_Barnyard2_set_up_guide\">https:\/\/redmine.openinfosecfoundation.org\/projects\/suricata\/wiki\/Suricata_Snorby_and_Barnyard2_set_up_guide<\/a>       <br \/><a title=\"https:\/\/redmine.openinfosecfoundation.org\/projects\/suricata\/wiki\/Basic_Setup\" href=\"https:\/\/redmine.openinfosecfoundation.org\/projects\/suricata\/wiki\/Basic_Setup\">https:\/\/redmine.openinfosecfoundation.org\/projects\/suricata\/wiki\/Basic_Setup<\/a><\/p>\n<\/blockquote>\n<p>&#160;<\/p>\n<p>Snorby \u304c\u7a3c\u50cd\u3059\u308b\u3068\u3053\u3093\u306a\u611f\u3058\u306e\u753b\u9762\u304c\u51fa\u307e\u3059\uff1a<\/p>\n<p><a href=\"http:\/\/mimumimu.net\/blog\/wp-content\/uploads\/2014\/05\/image17.png\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"image\" src=\"http:\/\/mimumimu.net\/blog\/wp-content\/uploads\/2014\/05\/image_thumb17.png\" width=\"524\" height=\"416\" \/><\/a><\/p>\n<p>&#160;<\/p>\n<p>\u304b\u306a\u308a\u306e\u9577\u6587\u306a\u306e\u3067\u300c\u7d9a\u304d\u3092\u8aad\u3080\u300d\u3092\u4f7f\u3063\u3066\u3044\u3063\u305f\u3093\u5207\u308a\u307e\u3059\u30fb\u30fb<\/p>\n<p><!--more--><\/p>\n<hr \/>\n<h3>\uff11\uff0e\u4e8b\u524d\u6e96\u5099<\/h3>\n<p>\u4e8b\u524d\u306b\u30d7\u30ed\u30df\u30b9\u30ad\u30e3\u30b9\u30e2\u30fc\u30c9\u3092\u6709\u52b9\u306b\u3057\u3066\u304a\u304d\u307e\u3059\u3002    <br \/>\u3042\u3068\u306f\u3001\u4f59\u8a08\u306a\u3053\u3068\u3092\u558b\u3089\u306a\u3044\u3088\u3046\u306b\u3044\u308d\u3044\u308d\u3044\u3058\u3063\u3066\u307f\u308b\u3002<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:d89678ed-5caa-4004-828e-a7b9d95d4bad\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: text;\"># vim \/etc\/sysconfig\/network-scripts\/ifcfg-eth0\n\nDEVICE=eth0\nTYPE=Ethernet\nONBOOT=yes\nBOOTPROTO=static\nPROMISC=yes\nUSERCTL=no\nPEERDNS=no<\/pre>\n<\/div>\n<p>\u79c1\u306e\u5834\u5408\u306f\u3053\u3093\u306a\u611f\u3058\u3067\u3002<\/p>\n<hr \/>\n<h3>\uff12\uff0eSuricata \u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u305f\u3081\u306e\u6e96\u5099<\/h3>\n<p>\u5fc5\u8981\u306a\u30d1\u30c3\u30b1\u30fc\u30b8\u304c epel \u306b\u3042\u308b\u306e\u3067\u5165\u308c\u3066\u304a\u304d\u307e\u3059\u3002<\/p>\n<p>\u5177\u4f53\u7684\u306b\u306f <\/p>\n<p><a href=\"http:\/\/ftp.iij.ad.jp\/pub\/linux\/fedora\/epel\/\">http:\/\/ftp.iij.ad.jp\/pub\/linux\/fedora\/epel\/<\/a><\/p>\n<p>\u3042\u305f\u308a\u304b\u3089\u3001\u81ea\u5206\u306e\u74b0\u5883\u306b\u3042\u3063\u305f epel-release \u3092\u53d6\u3063\u3066\u304d\u3066\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u3066\u304a\u304d\u307e\u3059\u3002<\/p>\n<p>&#160;<\/p>\n<p>\u79c1\u306e\u5834\u5408\u306f\u3053\u3093\u306a\u611f\u3058\uff1a<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:a668f0db-19c0-443c-91f8-120430019e40\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">rpm -ivh http:\/\/ftp.iij.ad.jp\/pub\/linux\/fedora\/epel\/6\/x86_64\/epel-release-6-8.noarch.rpm<\/pre>\n<\/div>\n<p>&#160;<\/p>\n<p>\u7d9a\u3044\u3066\u3001\u30d3\u30eb\u30c9\u306b\u5fc5\u8981\u306a\u3082\u306e\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\uff1a<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:45f2d011-53c3-49f3-ab35-92f04b3c751a\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">yum install gcc ruby-devel rubygems pcre-devel libyaml-devel libnet-devel libpcap-devel libcap-ng-devel file-devel zlib-devel rpm-build<\/pre>\n<\/div>\n<p>&#160;<\/p>\n<p>\u5f8c\u3067 RPM \u30d1\u30c3\u30b1\u30fc\u30b8\u306b\u307e\u3068\u3081\u308b\u305f\u3081\u306b\u4f7f\u3046 fpm \u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\uff1a<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:b339e8c7-b06d-44d7-a425-6c87f57c7ba7\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">gem install fpm<\/pre>\n<\/div>\n<hr \/>\n<h3>\uff13\uff0eSuricata \u3092\u30b3\u30f3\u30d1\u30a4\u30eb<\/h3>\n<p>\u4e0b\u8a18 URL \u304b\u3089 suricata \u306e\u6700\u65b0\u30d0\u30fc\u30b8\u30e7\u30f3\u3092\u53d6\u3063\u3066\u304d\u307e\u3059\u3002<\/p>\n<p><a title=\"http:\/\/www.openinfosecfoundation.org\/index.php\/download-suricata\" href=\"http:\/\/www.openinfosecfoundation.org\/index.php\/download-suricata\">http:\/\/www.openinfosecfoundation.org\/index.php\/download-suricata<\/a><\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:4d3525a8-1d1e-4dde-8cc8-cb22f313ef4c\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">wget http:\/\/www.openinfosecfoundation.org\/download\/suricata-2.0.tar.gz<\/pre>\n<\/div>\n<p>&#160;<\/p>\n<p>\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u305f\u30d5\u30a1\u30a4\u30eb\u3092\u5c55\u958b\u3057\u3066\u305d\u306e\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306b\u79fb\u52d5\u3057\u307e\u3059\u3002<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:6e394266-608e-4398-ba1e-4559a8f29be5\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">tar zxvf suricata-2.0.tar.gz\ncd suricata-2.0<\/pre>\n<\/div>\n<p>\u5148\u307b\u3069\u5c55\u958b\u3057\u305f\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306b\u79fb\u52d5\u3057\u3066<\/p>\n<p><strong>prefix=\/usr\/ <\/p>\n<p>sysconfdir=\/etc\/<\/strong> <\/p>\n<p>localstatedir=\/var\/<\/p>\n<p>\u3067 configure \u3092\u52d5\u304b\u3057\u307e\u3059\u3002 <\/p>\n<p>\uff08 QEMU\/KVM \u74b0\u5883\u3067\u306f\u3053\u308c\u306b\u52a0\u3048\u3066 \u201c\u2014disable-gccmarch-native\u201d \u3092\u4ed8\u3051\u308b\u3068\u3088\u3044\u305d\u3046\u3067\u3059\u3002\uff09<\/p>\n<p>configure \u304c\u7d42\u308f\u3063\u305f\u3089 make<\/p>\n<p>\u6700\u5f8c <strong>make install \u3092\u3059\u308b\u3068\u304d\u306b DESTDIR=\/tmp\/suricata<\/strong> <strong>\u3092\u4ed8\u3051\u3066<\/strong> install \u3057\u307e\u3059\u3002<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:30ed3c4e-4e8d-48fa-9cbe-3d4c90049b57\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">rm -rf \/tmp\/suricata\n.\/configure --prefix=\/usr\/ --sysconfdir=\/etc\/ --localstatedir=\/var\/\nmake -j8\nmake install DESTDIR=\/tmp\/suricata<\/pre>\n<\/div>\n<hr \/>\n<h3>\uff14\uff0eSuricata \u306e\u30d1\u30c3\u30b1\u30fc\u30b8\u3092\u4f5c\u3063\u3066\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/h3>\n<p>fpm \u30b3\u30de\u30f3\u30c9\u3092\u4f7f\u3063\u3066\u3055\u304f\u3063\u3068\u3002<\/p>\n<p>\u30fb\u30fb\u3053\u306e\u8fba\u306b\u3064\u3044\u3066\u306e\u8a73\u3057\u3044\u5185\u5bb9\u306f <\/p>\n<p><a href=\"https:\/\/mimumimu.net\/blog\/2014\/05\/12\/fpm-%e3%82%92%e4%bd%bf%e3%81%a3%e3%81%a6%e4%bb%bb%e6%84%8f%e3%81%ae%e3%83%97%e3%83%ad%e3%82%b0%e3%83%a9%e3%83%a0%e3%82%92-rpm-%e3%81%ab%e3%81%be%e3%81%a8%e3%82%81%e3%81%a6%e3%81%bf%e3%82%8b%e3%80%82\/\">fpm \u3092\u4f7f\u3063\u3066\u4efb\u610f\u306e\u30d7\u30ed\u30b0\u30e9\u30e0\u3092 rpm \u306b\u307e\u3068\u3081\u3066\u307f\u308b\u3002<\/a> \u3092\u53c2\u7167\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>&#160;<\/p>\n<p>\u30fb\u30fb\u3063\u3066\u3053\u3068\u3067\u3055\u304f\u3063\u3068\u3002<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:f02d8057-d4b7-4eef-93d3-9af46b1e89ba\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">cd ~\nfpm -s dir -t rpm -n suricata -v 2.0 -C \/tmp\/suricata -p suricata-2.0.rpm .\nrm -rf \/tmp\/suricata<\/pre>\n<\/div>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:5e711074-ac6f-46e6-aebd-50fe8ef2b576\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">su\nrpm -ivh suricata-2.0.rpm\nexit<\/pre>\n<\/div>\n<p>&#160;<\/p>\n<hr \/>\n<h3>\uff15\uff0eSuricata \u306e\u8a2d\u5b9a<\/h3>\n<p><a title=\"https:\/\/redmine.openinfosecfoundation.org\/projects\/suricata\/wiki\/Basic_Setup\" href=\"https:\/\/redmine.openinfosecfoundation.org\/projects\/suricata\/wiki\/Basic_Setup\">https:\/\/redmine.openinfosecfoundation.org\/projects\/suricata\/wiki\/Basic_Setup<\/a><\/p>\n<p>\u3053\u306e\u8fba\u306e\u30da\u30fc\u30b8\u3092\u898b\u306a\u304c\u3089\u30fb\u30fb\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<p>\u5148\u307b\u3069\u30d3\u30eb\u30c9\u3057\u305f\u30bd\u30fc\u30b9\u30b3\u30fc\u30c9\u306e\u7f6e\u3044\u3066\u3042\u308b\u5834\u6240\u306b\u79fb\u52d5\u3057\u3001 <\/p>\n<p>\u7ba1\u7406\u8005\u6a29\u9650\u3067 make install-full \u3092\u3059\u308b\u3068\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u3068\u30eb\u30fc\u30eb\u304c\u826f\u3044\u611f\u3058\u306b\u5165\u308a\u307e\u3059\u306e\u3067<\/p>\n<p>\u3053\u308c\u3092\u4f7f\u3063\u3066\u307f\u307e\u3059\u3002<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:1eba050e-006b-4697-a1b4-9f90532ccdb0\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">su\ncd suricata-2.0\nmake install-full<\/pre>\n<\/div>\n<p>\u3053\u308c\u304c\u5b8c\u4e86\u3057\u305f\u3089\u3001 \/etc\/suricata\/suricata.yaml \u3092\u81ea\u5206\u306e\u74b0\u5883\u306b\u5408\u308f\u305b\u3066\u5909\u66f4\u3057\u307e\u3059\u3002<\/p>\n<p>\u30fb\u30fb\u3044\u308d\u3044\u308d\u3068\u8a2d\u5b9a\u9805\u76ee\u306f\u3042\u308a\u307e\u3059\u304c\u3001\u3068\u308a\u3042\u3048\u305a\u74b0\u5883\u306b\u95a2\u3057\u3066\u306f <\/p>\n<p><strong>vars: \u306e\u4e2d\u306e address-groups: \u306e\u5909\u66f4<\/strong>\u3092\u3059\u308c\u3070\u5927\u4e08\u592b\u304b\u3068\u601d\u3044\u307e\u3059\u3002<\/p>\n<p>\uff08\u5fc5\u8981\u306b\u5fdc\u3058\u3066 host-os-policy \u3084 port-groups \u306a\u3069\u3002\uff09<\/p>\n<p>\u30fb\u30fb\u79c1\u306e\u5834\u5408\u306f<\/p>\n<p>HOME_NET: \u201c192.168.1.0\/24\u201d<\/p>\n<p>\u306b\u5909\u66f4\u3002\u3042\u3068\u306f HTTP_SERVERS \u3082\u3061\u3087\u3053\u3063\u3068\u5909\u3048\u307e\u3057\u305f\u3002<\/p>\n<p>&#160;<\/p>\n<p>\u3053\u306e\u6642\u70b9\u3067<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:d4f4ad09-7b5d-422c-b02e-360620de1894\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">suricata -c \/etc\/suricata\/suricata.yaml -i eth0<\/pre>\n<\/div>\n<p>\u3068\u304b\u6253\u3063\u3066\u52d5\u4f5c\u3059\u308c\u3070\u3001\u3053\u3053\u307e\u3067\u306e\u8a2d\u5b9a\u306f\u5b8c\u4e86\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<hr \/>\n<h3>\uff16\uff0eBarnyard \u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/h3>\n<p>\u5fc5\u8981\u306a\u3084\u3064\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:27780507-6f65-48c2-952f-3e856edeba99\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: text;\">yum install readline-devel libxml2-devel libxslt-devel mysql-devel mysql-libs mysql-server urw-fonts libyaml-devel gdbm-devel libffi-devel ImageMagick-devel git apr-devel apr-util-devel httpd-devel curl-devel gcc-c++ libtool<\/pre>\n<\/div>\n<p>&#160;<\/p>\n<p>Barnyard \u3092git ( <a title=\"https:\/\/github.com\/firnsy\/barnyard2.git\" href=\"https:\/\/github.com\/firnsy\/barnyard2.git\">https:\/\/github.com\/firnsy\/barnyard2.git<\/a> ) \u304b\u3089\u53d6\u3063\u3066\u304d\u307e\u3059<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:de74f60e-74e3-41a2-9b9d-58f7d71db1e6\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: text;\">cd ~\ngit clone https:\/\/github.com\/firnsy\/barnyard2.git<\/pre>\n<\/div>\n<p>&#160;<\/p>\n<p>\u307e\u305f\u3053\u308c\u3082 rpm \u5316\u3057\u3066\u304b\u3089\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u307e\u3059\u306e\u3067\u3001 <\/p>\n<p>autogen.sh \u3092\u547c\u3093\u3067 configure \u3092\u751f\u6210\u3057\u3001<\/p>\n<p>\u3053\u308c\u3092 \u201c\u2014prefix=\/usr \u2013with-mysql \u2013with-mysql-libraries=\/usr\/lib64\/mysql\u201d \u3067\u547c\u3073\u51fa\u3057\u307e\u3059\u3002<\/p>\n<p>\u305d\u306e\u5f8c\u3001 make,&#160; make install DESTDIR=~\/barnyard, fpm \u306e\u6d41\u308c\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:bce2bb24-973b-4080-af72-74744364c827\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">.\/configure --prefix=\/usr --with-mysql --with-mysql-libraries=\/usr\/lib64\/mysql\nmake -j8\nmake install DESTDIR=~\/barnyard\ncd ~\nfpm -s dir -t rpm -n barnyard -v 2.1.12 -C ~\/barnyard -p barnyard-2.1.12.rpm usr\/\nrm -rf barnyard\n\nsu\nrpm -ivh barnyard-2.1.12.rpm<\/pre>\n<\/div>\n<p>\u305d\u308c\u3068\u3001\u5148\u307b\u3069 clone \u3057\u305f\u30d5\u30a9\u30eb\u30c0\u5185\u306b\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u304c\u3042\u308b\u306e\u3067\u3053\u308c\u3092 surikata \u4ee5\u4e0b\u306b\u30b3\u30d4\u30fc<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:68c458a0-3a39-44a7-9f94-94cb65822fe7\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">cd barnyard2\ncp etc\/barnyard2.conf \/etc\/suricata\/<\/pre>\n<\/div>\n<p>\u6700\u5f8c\u306b \/var\/log\/barnyard2 \u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u3092\u4f5c\u3063\u3066\u304a\u304d\u307e\u3059\u3002<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:52214264-44e7-4fbc-ab92-79a9dd2c5d19\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">mkdir \/var\/log\/barnyard2<\/pre>\n<\/div>\n<hr \/>\n<h3>\uff17\uff0eBarnyard \u306e\u8a2d\u5b9a<\/h3>\n<p>\u30c7\u30fc\u30bf\u683c\u7d0d\u7528\u306e\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u3068\u30e6\u30fc\u30b6\u3092\u4f5c\u3063\u3066\u304a\u304d\u307e\u3059\u3002<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:4007ab1a-7195-4077-8c19-c61e08d71ec5\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: text;\">mysql&gt; CREATE DATABASE \u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u540d;\nmysql&gt; GRANT ALL ON \u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u540d.* to \u30e6\u30fc\u30b6\u540d@localhost;\nmysql&gt; FLUSH PRIVILEGES;\nmysql&gt; SET PASSWORD FOR \u30e6\u30fc\u30b6\u540d@localhost=password('\u30d1\u30b9\u30ef\u30fc\u30c9');<\/pre>\n<\/div>\n<p>\u30fb\u30fb\u4e0a\u8a18\u306b\u4e0a\u3052\u305f\u3088\u3046\u306a\u6d41\u308c\u3067\u3001\u4efb\u610f\u306e\u540d\u524d\u3067\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u3092\u4f5c\u3063\u3066\u3001 <\/p>\n<p>\u305d\u306e\u30e6\u30fc\u30b6\u306b\u6a29\u9650\u3092\u4e0e\u3048\u307e\u3059\u3002<\/p>\n<p>&#160;<\/p>\n<p>\u79c1\u306e\u5834\u5408\u306f\u9069\u5f53\u306b\u3053\u3093\u306a\u611f\u3058\u306b\uff1a \uff08\u30d1\u30b9\u30ef\u30fc\u30c9\u306f\u5909\u3048\u307e\u3057\u305f\u3088\u3001\u3082\u3061\u308d\u3093\uff01\uff09<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:c5cd046f-31b0-4a67-9db0-f6ff98102fbb\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: text;\">mysql&gt; create database barnyard;\nmysql&gt; grant all on barnyard.* to barnyard@localhost;\nmysql&gt; flush privileges;\nmysql&gt; set password for barnyard@localhost=password('yuyushiki');<\/pre>\n<\/div>\n<p>&#160;<\/p>\n<p>\/etc\/suricata\/barnyard2.conf \u3092\u7de8\u96c6\u3057\u307e\u3059\u3002 <\/p>\n<p>\u4e2d\u306e \/etc\/snort \u3092 \/etc\/suricata \u306b\u5909\u3048\u3066\u3044\u304f\u611f\u3058\u3067\u3059\u3002<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:3e9cb0d9-78d2-44f9-a757-97a3f8ba2f35\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\"># vim \/etc\/suricata\/barnyard2.conf\n\nconfig reference_file:      \/etc\/suricata\/reference.config\nconfig classification_file: \/etc\/suricata\/classification.config\nconfig gen_file:            \/etc\/suricata\/rules\/gen-msg.map\nconfig sid_file:            \/etc\/suricata\/rules\/sid-msg.map\n\n..\n\n#\u6700\u4e0b\u884c\u306b\u8ffd\u8a18\n\noutput database: log, mysql, user=barnyard password=yuyushiki dbname=barnyard host=localhost sensor_name=suricata<\/pre>\n<\/div>\n<p>&#160;<\/p>\n<p>\u6700\u5f8c\u306b \/etc\/suricata\/suricata.yaml \u306e logging outputs \u306b\u95a2\u3059\u308b\u90e8\u5206\u3092\u898b\u76f4\u3057\u3066\u5b8c\u4e86\u3067\u3059\u3002<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:84b613ac-11d9-48f3-a1e9-dd800e640b1c\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\"># vim \/etc\/suricata\/suricata.yaml\n\noutputs:\n - file:\n     enabled :yes  \u2190 \u3053\u3053\u304c YES \u306b\u306a\u3063\u3066\u3044\u308b\u304b\u3069\u3046\u304b\u3002 NO \u3060\u3063\u305f\u3089\u5909\u66f4\u3059\u308b\n\n - unified2-alert:\n   enabled : yes \u2190\u3053\u3053\u304c YES \u306b\u306a\u3063\u3066\u3044\u308b\u304b\u3069\u3046\u304b\u3002 NO \u3060\u3063\u305f\u3089\u5909\u66f4\u3059\u308b\n\n - stats:\n   enabled : no \u2190 \u3053\u3053\u306f NO \u306b\u306a\u3063\u3066\u3044\u308b\u304b\u3069\u3046\u304b\u3002 YES \u3060\u3068\u30c7\u30a3\u30b9\u30af\u3092\u5727\u8feb\u3059\u308b\u3002<\/pre>\n<\/div>\n<p>&#160;<\/p>\n<hr \/>\n<h3>\uff18\uff0eSnorby \u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/h3>\n<p>\u307e\u305a wkhtmltopdf \u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u307e\u3059\u3002<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:c2a1b7ed-28c7-472a-b386-8c827f0a298a\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">wget http:\/\/downloads.sourceforge.net\/project\/wkhtmltopdf\/0.12.0\/wkhtmltox-linux-amd64_0.12.0-03c001d.tar.xz\ntar Jxvf wkhtmltox-linux-amd64_0.12.0-03c001d.tar.xz<\/pre>\n<\/div>\n<p>&#160;<\/p>\n<p>\u3053\u306e\u307e\u307e\u30b3\u30d4\u30fc\u3059\u308b\u306e\u306f\u3042\u307e\u308a\u7cbe\u795e\u885b\u751f\u4e0a\u3088\u308d\u3057\u304f\u306a\u3044\u306e\u3067 rpm \u306b\u3057\u3066\u304b\u3089\u3002<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:073d04cb-92b1-4dbd-b9fa-17d289d57240\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">mv wkhtmltox usr\nfpm -s dir -t rpm -n wkhtmltox.rpm -v 0.12 -p wkhtmltox usr\/\nsu\nrpm -ivh wkhtmltox.rpm<\/pre>\n<\/div>\n<p>&#160;<\/p>\n<p>\u305d\u308c\u3068 ruby \u3092 1.9 \u7cfb\u3092\u5165\u308c\u308b\u5fc5\u8981\u304c\u3042\u308b\u306e\u3067 <\/p>\n<p>SPEC FILE \u3068\u30bd\u30fc\u30b9\u30b3\u30fc\u30c9\u3092\u53d6\u3063\u3066\u304d\u3066\u3001 rpmbuild \u3092\u884c\u3044\u307e\u3059\u3002<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:cbb29091-7f70-4a48-8a99-325625abcf36\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: text;\">cd ~\nmkdir -p rpmbuild\/{BUILD,BUILDROOT,RPMS,SOURCES,SPECS,SRPMS}\nwget ftp:\/\/ftp.ruby-lang.org\/pub\/ruby\/1.9\/ruby-1.9.3-p545.tar.gz -P rpmbuild\/SOURCES\nwget https:\/\/raw.github.com\/imeyer\/ruby-1.9.3-rpm\/master\/ruby19.spec -P rpmbuild\/SPECS\nrpmbuild -bb rpmbuild\/SPECS\/ruby19.spec<\/pre>\n<\/div>\n<p>\u6c17\u9577\u306b\u5f85\u3064\u3068\u3001rpmbuild\/RPMS\/(\u30a2\u30fc\u30ad\u30c6\u30af\u30c1\u30e3)\/ \u306b rpm \u30d5\u30a1\u30a4\u30eb\u304c\u3067\u304d\u3042\u304c\u3063\u3066\u3044\u307e\u3059\u306e\u3067 <\/p>\n<p>\u305d\u308c\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3002<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:ebb04439-c2fd-4de4-91ca-25289dc2a1cc\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">su\nrpm -Uvh ruby-1.9.3p545-1.el6.x86_64.rpm<\/pre>\n<\/div>\n<p>&#160;<\/p>\n<p>\u7d9a\u3044\u3066 ruby \u306e\u5fc5\u8981\u306a\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:a568042d-125b-40e5-bd33-99910fdfe874\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">gem install bundler<\/pre>\n<\/div>\n<p>&#160;<\/p>\n<p>Apache \u306b passenger \u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:7049d480-85f3-4092-a63f-bcb523fee374\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">gem install passenger\npassenger-install-apache2-module<\/pre>\n<\/div>\n<p>&#160;<\/p>\n<p>\u3044\u308d\u3044\u308d\u3068\u805e\u304b\u308c\u307e\u3059\u304c\u3001\u30c7\u30d5\u30a9\u30eb\u30c8\u3067\u5927\u4e08\u592b\u3067\u3059\u3002 <\/p>\n<p>\u305d\u3057\u3066\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u304c\u5b8c\u4e86\u3057\u305f\u3089\u3001<\/p>\n<p>\u4e0b\u8a18\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3066\u57fa\u672c\u7684\u306a\u8a2d\u5b9a\u3092\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u306b\u66f8\u304d\u8fbc\u307e\u305b\u307e\u3059\u3002<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:66a9232c-d1df-4e7c-b8ff-f9d44003d302\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">passenger-install-apache2-module --snippet &gt; \/etc\/httpd\/conf.d\/passenger.conf<\/pre>\n<\/div>\n<p>\u66f8\u304d\u8fbc\u307e\u305b\u305f\u3089\u3001\u3044\u304f\u3064\u304b\u8ffd\u52a0\u9805\u76ee\u3092\u8a18\u8ff0\u3057\u307e\u3059\u3002<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:50982342-4f56-437b-a8a6-764380e69dfe\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\"># vim \/etc\/httpd\/conf.d\/passenger.conf\n\nLoadModule passenger_module \/usr\/lib64\/ruby\/gems\/1.9.1\/gems\/passenger-4.0.42\/buildout\/apache2\/mod_passenger.so\n&lt;IfModule mod_passenger.c&gt;\n  PassengerRoot \/usr\/lib64\/ruby\/gems\/1.9.1\/gems\/passenger-4.0.42\n  PassengerDefaultRuby \/usr\/bin\/ruby\n&lt;\/IfModule&gt;\n\n# \u3053\u3053\u304b\u3089\u4e0b\u3092\u8ffd\u8a18\n\nHeader always unset &quot;X-Powered-By&quot;\nHeader always unset &quot;X-Rack-Cache&quot;\nHeader always unset &quot;X-Content-Digest&quot;\nHeader always unset &quot;X-Runtime&quot;<\/pre>\n<\/div>\n<p>&#160;<\/p>\n<p>\u3067\u3082\u3063\u3066\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u306b\u30d5\u30a1\u30a4\u30eb\u3092\u8a2d\u7f6e<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:17a386fb-f104-4a2c-a353-2c986fc40276\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">cd \/var\/www\/html\/\ngit clone https:\/\/github.com\/Snorby\/snorby.git\ncd \/var\/www\/html\/snorby\/config\/\ncp database.yml.example database.yml\ncp snorby_config.yml.example snorby_config.yml\nchown -R apache:apache \/var\/www\/html\/snorby<\/pre>\n<\/div>\n<p>&#160;<\/p>\n<p>database.yml \u3092\u5909\u66f4\u3057\u3066\u3001 Barnyard \u3067\u8a2d\u5b9a\u3057\u305f\u3068\u304d\u306e\u8a2d\u5b9a\u306b\u5408\u308f\u305b\u308b<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:c0136ec5-4f95-430b-8cba-789ca37e83f4\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: text;\">#vim database.yml\n\nbarnyard: &amp;barnyard\n  adapter: mysql\n  username: barnyard\n  password: &quot;yuyushiki&quot; # Example: password: &quot;s3cr3tsauce&quot;\n  host: localhost\n\ndevelopment:\n  database: barnyard\n  &lt;&lt;: *barnyard\n\ntest:\n  database: barnyard\n  &lt;&lt;: *barnyard\n\nproduction:\n  database: barnyard\n  &lt;&lt;: *barnyard<\/pre>\n<\/div>\n<p>&#160;<\/p>\n<p>\u4e00\u3064\u4e0a\u306e\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306b\u79fb\u52d5\u3057\u3001 <\/p>\n<p>\u307e\u305a Gemfile \u306e \u201c\u2019rake\u2019,\u20190.9.2\u2019 \u3068\u306a\u3063\u3066\u3044\u308b\u90e8\u5206\u3092 \u2018&gt; 0.9.2\u2019 \u306b\u66f8\u304d\u63db\u3048\u307e\u3059\u3002<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:763036fb-73d1-4dc7-ae61-fc5caf306f49\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\"># vim \/var\/www\/html\/snorby\/Gemfile\n\n# gem 'rake' '0.9.2' \u3092\u4e0b\u8a18\u306e\u3088\u3046\u306b\u66f8\u304d\u63db\u3048\u308b\ngem 'rake' '&gt; 0.9.2'<\/pre>\n<\/div>\n<p>\u305d\u306e\u5f8c\u3001 Gemfile.lock \u3092\u524a\u9664\u3057\u305f\u4e0a\u3067\u3001bundle install,&#160; rake snorby:setup \u3092\u884c\u3044\u307e\u3059\u3002<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:a2d05405-f253-4374-a7e8-97874495bf41\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">rm Gemfile.lock\n\nsu\nbundle install # CentOS \u74b0\u5883\u3060\u3068 sudo \u304c\u6b63\u5e38\u306b\u52d5\u304b\u306a\u3044\u5834\u5408\u3082\u3042\u308b\u305f\u3081\nexit\n\nbundle exec rake snorby:setup<\/pre>\n<\/div>\n<p>&#160;<\/p>\n<p>\u305d\u3057\u3066 \/etc\/httpd\/conf.d\/passenger.conf \u306b\u8a2d\u5b9a\u3092\u66f8\u304d\u52a0\u3048\u3066\u3001\u30b5\u30fc\u30d0\u3092\u7acb\u3061\u4e0a\u3052\u307e\u3059\u3002<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:d9e106dd-42c7-4221-8707-a3dd63440656\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\"># vim \/etc\/httpd\/conf.d\/passenger.conf\n\nLoadModule passenger_module \/usr\/lib64\/ruby\/gems\/1.9.1\/gems\/passenger-4.0.42\/buildout\/apache2\/mod_passenger.so\n&lt;IfModule mod_passenger.c&gt;\n  PassengerRoot \/usr\/lib64\/ruby\/gems\/1.9.1\/gems\/passenger-4.0.42\n  PassengerDefaultRuby \/usr\/bin\/ruby\n&lt;\/IfModule&gt;\n\nHeader always unset &quot;X-Powered-By&quot;\nHeader always unset &quot;X-Rack-Cache&quot;\nHeader always unset &quot;X-Content-Digest&quot;\nHeader always unset &quot;X-Runtime&quot;\n\n# \u4e0b\u8a18\u3092\u8ffd\u8a18 ( Server Name \u7b49\u306f\u5404\u74b0\u5883\u306b\u5408\u308f\u305b\u308b )\n\n&lt;VirtualHost *:80&gt;\n        ServerName ids.contoso.com\n        DocumentRoot \/var\/www\/html\/snorby\/public\n\n        &lt;Directory &quot;\/var\/www\/html\/snorby\/public&quot;&gt;\n                AllowOverride all\n                Order deny,allow\n                Allow from all\n                Options -MultiViews\n        &lt;\/Directory&gt;\n&lt;\/VirtualHost&gt;<\/pre>\n<\/div>\n<p>&#160;<\/p>\n<p>\u3053\u3053\u306e\u72b6\u614b\u3067\u3001 httpd \u3092\u958b\u59cb\u3055\u305b\u3066\u63a5\u7d9a\u3057\u305f\u3068\u304d\u306b\u3001 <\/p>\n<p>\u826f\u3044\u611f\u3058\u3067\u753b\u9762\u304c\u51fa\u3066\u304f\u308c\u3070\u8a2d\u5b9a\u306f\u6210\u529f\u3067\u3059\u3002<\/p>\n<hr \/>\n<h3>\uff19\uff0e\u3059\u3079\u3066\u3092\u7d44\u307f\u5408\u308f\u305b\u308b<\/h3>\n<p>\u3053\u3053\u307e\u3067\u6765\u308c\u3070\u5f8c\u306f\u3082\u3046\u5c11\u3057\u3067\u3059\u3002<\/p>\n<p>1. suricata \u3092\u8d77\u52d5\u3055\u305b\u308b<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:201ad89b-a12d-425e-b12b-0d31d1f8959c\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">suricata -c \/etc\/suricata\/suricata.yaml -i eth0 -D<\/pre>\n<\/div>\n<p>2. barnyard2 \u3092\u8d77\u52d5\u3055\u305b\u308b<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:967532c0-87ce-4d7a-babf-531db165926f\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: text;\">barnyard2 -c \/etc\/suricata\/barnyard2.conf -d \/var\/log\/suricata -f unified2.alert -w \/var\/log\/suricata\/suricata.waldo -D<\/pre>\n<\/div>\n<p>3. snorby \u306b\u30ed\u30b0\u30a4\u30f3\u3059\u308b<\/p>\n<p>\u521d\u671f\u5024\u306f\u4e0b\u8a18\u306e\u901a\u308a<\/p>\n<p>ID : <a href=\"mailto:snorby@snorby.org\">snorby@snorby.org<\/a><\/p>\n<p>Pass : snorby<\/p>\n<p>&#160;<\/p>\n<p>\u3053\u308c\u3067\u30ed\u30b0\u30a4\u30f3\u3067\u304d\u308c\u3070\u8a2d\u5b9a\u304c\u3059\u3079\u3066\u5b8c\u4e86\u3057\u305f\u3053\u3068\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<p>\u3082\u3057 httpd \u3084 mysqld \u304c\u8d77\u52d5\u6642\u306b\u8d77\u52d5\u3057\u306a\u3044\u3088\u3046\u306b\u306a\u3063\u3066\u3044\u308c\u3070\u3001<\/p>\n<p>chkconfig httpd on <\/p>\n<p>chkconfig mysqld on<\/p>\n<p>\u7b49\u3092\u5b9f\u884c\u3057\u3066\u8a2d\u5b9a\u3092\u884c\u3046\u3068\u826f\u3044\u304b\u3068\u601d\u3044\u307e\u3059\u3002<\/p>\n<p>&#160;<\/p>\n<p>\u307e\u305f\u3001\u8d77\u52d5\u3059\u308b\u305f\u3073\u306b suricata \u3084 barnyard2 \u3092\u8d77\u52d5\u3059\u308b\u306e\u306f\u9762\u5012\u304f\u3055\u3044\u3001\u3068\u3044\u3046\u5834\u5408\u306f <\/p>\n<p>\/etc\/rc.local \u306b\u8a18\u8ff0\u3092\u52a0\u3048\u3066\u304a\u304f\u3068\u8d77\u52d5\u6642\u306b\u5b9f\u884c\u3055\u308c\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<p>&#160;<\/p>\n<blockquote>\n<p>2014\/05\/13 03:40 \u8ffd\u8a18\uff1a<\/p>\n<p>The Snorby worker is not currently running. \u3068\u8868\u793a\u3055\u308c\u3066 <\/p>\n<p>\u52d5\u304b\u306a\u3044\u3053\u3068\u304c\u7d50\u69cb\u3042\u308b\u3088\u3046\u3067\u3059\u3002<\/p>\n<p>\u3053\u306e\u5834\u5408\u3001snorby \u3092\u5c55\u958b\u3057\u305f\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306b\u79fb\u52d5\u3057\u3001 <\/p>\n<p>ruby script\/delayed_job start<\/p>\n<p>\u3092\u5b9f\u884c\u3059\u308b\u3068\u8868\u793a\u304c\u6d88\u3048\u3066\u52d5\u304d\u51fa\u3057\u307e\u3059\u3002<\/p>\n<p>\u30fb\u30fb\u3082\u3057\u304b\u3059\u308b\u3068 \/etc\/rc.local \u7b49\u306b\u5165\u308c\u3066\u304a\u304f\u5fc5\u8981\u304c\u3042\u308b\u304b\u3082\u3057\u308c\u307e\u305b\u3093\u3002<\/p>\n<p>\u79c1\u306f <\/p>\n<p>pushd \/var\/www\/html\/snorby<\/p>\n<p>ruby script\/delayed_job start<\/p>\n<p>popd<\/p>\n<p>\u306a\u3093\u3066\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u66f8\u3044\u3066\u307f\u307e\u3057\u305f\u30fb\u30fb\u3002<\/p>\n<\/blockquote>\n<p>&#160;<\/p>\n<hr \/>\n<h3>10. \u81ea\u52d5\u7684\u306b\u30eb\u30fc\u30eb\u3092\u66f4\u65b0\u3059\u308b (oinkmaster)<\/h3>\n<p><a title=\"http:\/\/sourceforge.net\/projects\/oinkmaster\/files\/oinkmaster\/\" href=\"http:\/\/sourceforge.net\/projects\/oinkmaster\/files\/oinkmaster\/\">http:\/\/sourceforge.net\/projects\/oinkmaster\/files\/oinkmaster\/<\/a><\/p>\n<p>\u3053\u306e\u8fba\u304b\u3089 oinkmaster \u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3001 <\/p>\n<p>\u4e2d\u306e oinkmaster.pl \u3092 \/usr\/local\/bin \u3078\u3001 oinkmaster.conf \u3092 \/etc\/suricata\/ \u3078\u30b3\u30d4\u30fc<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:2ab5656e-da7f-408a-afe9-16d151e81aa1\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">tar zxvf oinkmaster.tar.gz\ncd oinkmaster-2.0\ncp oinkmaster.pl \/usr\/local\/bin\ncp oinkmaster.conf \/etc\/suricata\/<\/pre>\n<\/div>\n<p>oinkmaster.conf \u306e url \u3092 <\/p>\n<p><a href=\"http:\/\/rules.emergingthreats.net\/open\/suricata\/emerging.rules.tar.gz\">http:\/\/rules.emergingthreats.net\/open\/suricata\/emerging.rules.tar.gz<\/a><\/p>\n<p>\u3078\u66f8\u304d\u63db\u3048<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:701c4dbd-7410-414f-a420-a6305b9cf046\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\"># vim \/etc\/suricata\/oinkmaster.conf\n\nurl = http:\/\/rules.emergingthreats.net\/open\/suricata\/emerging.rules.tar.gz<\/pre>\n<\/div>\n<p>\/etc\/suricata\/suricata.yaml \u306e classification-file \u3068 reference-config-file \u306e\u9805\u3092\u5909\u66f4 <\/p>\n<p>(rules \u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u3092\u898b\u306b\u884c\u304f\u3088\u3046\u306b\u3059\u308b)<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:2da3dc0f-47e9-406d-8a60-cac52432fd8e\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: text;\"># vim \/etc\/suricata\/suricata.yaml\n\nclassification-file: \/etc\/suricata\/rules\/classification.config\nreference-config-file: \/etc\/suricata\/rules\/reference.config<\/pre>\n<\/div>\n<p>&#160;<\/p>\n<p>\u5f8c\u306f \/etc\/suricata\/rules \u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306b\u5bfe\u3057\u3066 oinkmaster \u3092\u5b9f\u884c\u3002<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:48d8a209-e593-47a5-abe5-a69b18b6fdd0\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">\/usr\/local\/bin\/oinkmaster.pl -C \/etc\/suricata\/oinkmaster.conf -o \/etc\/suricata\/rules<\/pre>\n<\/div>\n<p>&#160;<\/p>\n<p>\u3053\u308c\u306e\u3089\u66f4\u65b0\u4f5c\u696d\u3092\u81ea\u52d5\u3067\u884c\u3046\u5834\u5408\u306f\u3001<\/p>\n<p>\u3053\u3061\u3089\u306e\u30b5\u30a4\u30c8\u3067\u7d39\u4ecb\u3055\u308c\u3066\u3044\u308b\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u3061\u3087\u3063\u3068\u66f8\u304d\u63db\u3048\u308b\u3068\u53ef\u80fd\u3067\u3059\u3002 <\/p>\n<p><a title=\"http:\/\/centossrv.com\/snort-base.shtml\" href=\"http:\/\/centossrv.com\/snort-base.shtml\">http:\/\/centossrv.com\/snort-base.shtml<\/a><\/p>\n<p>\u3053\u3093\u306a\u98a8\u306b\uff1a<\/p>\n<div id=\"scid:f32c3428-b7e9-4f15-a8ea-c502c7ff2e88:3b1223bf-5e93-4509-8d02-69d65b55f653\" class=\"wlWriterSmartContent\" style=\"float: none; padding-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px\">\n<pre class=\"brush: bash;\">#!\/bin\/bash\n\n\/usr\/local\/bin\/oinkmaster.pl -C \/etc\/suricata\/oinkmaster.conf -o \/etc\/suricata\/rules 2&gt;&amp;1 1&gt; \/dev\/null<\/pre>\n<\/div>\n<p>&#160;<\/p>\n<hr \/>\n<p>\u304b\u306a\u308a\u306e\u9577\u6587\u3068\u306a\u308a\u307e\u3057\u305f\u304c\u3001 <\/p>\n<p>\u3053\u308c\u306b\u95a2\u3057\u3066\u306e\u65e5\u672c\u8a9e\u8cc7\u6599\u304c\u3042\u307e\u308a\u306a\u3044\u3001\u3068\u3044\u3046\u3068\u3053\u308d\u3067\u3001\u5c11\u3057\u3067\u3082\u53c2\u8003\u306b\u306a\u308c\u3070\u5e78\u3044\u3067\u3059\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u3069\u3046\u3082\u307f\u3080\u3089\u3067\u3059\u3002 IDS \u3068\u3044\u3046\u3068 Snort \u3068\u3044\u3046\u30a4\u30e1\u30fc\u30b8\u3082\u591a\u3044\u304b\u3068\u601d\u3044\u307e\u3059\u304c\u3001 \u3075\u3068 Google \u306a\u30da\u30fc\u30b8\u3092\u3055\u307e\u3088\u3063\u3066\u3044\u305f\u3089 Suricata \u3068\u3044\u3046\u3082\u306e\u3092\u898b\u3064\u3051\u307e\u3057\u305f\u306e\u3067\u3001 \u3053\u308c\u3092\u5165\u308c\u3066\u307f\u3088\u3046\u304b\u3068\u3002 \u74b0\u5883\u3068\u3057 [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13,19,1],"tags":[516,517,518,300],"class_list":["post-5080","post","type-post","status-publish","format-standard","hentry","category-unix-linux","category-ruby","category-other","tag-centos-6-5","tag-snorby","tag-suricata","tag-300"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/posts\/5080","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/comments?post=5080"}],"version-history":[{"count":0,"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/posts\/5080\/revisions"}],"wp:attachment":[{"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/media?parent=5080"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/categories?post=5080"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/tags?post=5080"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}