Building sguil-sensor-0.8.0.txz (origin /buildshare/ports/355755/security/sguil-sensor) for powerpc-10-0 on XXX slot1: created x distfiles/ x distfiles/sguil-sensor-0.8.0.tar.gz x packages/ x packages/automake-wrapper-20131203.txz x packages/gmake-3.82_1.txz x packages/gettext-0.18.3.1_1.txz x packages/autoconf-wrapper-20131203.txz x packages/m4-1.4.17_1,1.txz x packages/automake-1.14.txz x packages/tcltls-1.6_1.txz x packages/perl5-5.16.3_10.txz x packages/tclX-8.4_3.txz x packages/tcl86-8.6.1.txz x packages/help2man-1.43.3_1.txz x packages/barnyard2-sguil-1.13.txz x packages/libtool-2.4.2_3.txz x packages/pkg-1.2.7_2.txz x packages/p5-Locale-gettext-1.05_3.txz x packages/autoconf-2.69.txz ELF ldconfig path: /lib /usr/lib /usr/lib/compat Make depends ===> sguil-sensor-0.8.0 depends on file: /usr/local/sbin/pkg - not found ===> Verifying install for /usr/local/sbin/pkg in /buildshare/ports/355755/ports-mgmt/pkg ===> Installing existing package /packages/pkg-1.2.7_2.txz Installing pkg-1.2.7_2... done If you are upgrading from the old package format, first run: # pkg2ng ===> Returning to build of sguil-sensor-0.8.0 ===> sguil-sensor-0.8.0 depends on package: tcltls>=0 - not found ===> Verifying install for tcltls>=0 in /buildshare/ports/355755/devel/tcltls ===> Installing existing package /packages/tcltls-1.6_1.txz Installing tcltls-1.6_1...Installing tcl86-8.6.1... done done ===> Returning to build of sguil-sensor-0.8.0 ===> sguil-sensor-0.8.0 depends on executable: barnyard2 - not found ===> Verifying install for barnyard2 in /buildshare/ports/355755/security/barnyard2-sguil ===> Installing existing package /packages/barnyard2-sguil-1.13.txz Installing barnyard2-sguil-1.13... done Read the notes in the barnyard2.conf file for how to configure /usr/local/etc/barnyard2.conf after installation. For addtional information see the Securixlive FAQ at http://www.securixlive.com/barnyard2/faq.php. In order to enable barnyard2 to start on boot, you must edit /etc/rc.conf with the appropriate flags, etc. See the FreeBSD Handbook for syntax: http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/configtuning-rcng.html For the various options available, type %25 barnyard2 -h after install or read the options in the startup script - in /usr/local/etc/rc.d. Barnyard2 can process unified2 files from snort or suricata. It can also interact with snortsam firewall rules as well as the sguil-sensor. Those ports must be installed separately if you wish to use them. ************************************************************************ ===> Returning to build of sguil-sensor-0.8.0 ===> sguil-sensor-0.8.0 depends on file: /usr/local/lib/tclx8.4/tclx.tcl - not found ===> Verifying install for /usr/local/lib/tclx8.4/tclx.tcl in /buildshare/ports/355755/lang/tclX ===> Installing existing package /packages/tclX-8.4_3.txz Installing tclX-8.4_3... done ===> Returning to build of sguil-sensor-0.8.0 Make install ===> sguil-sensor-0.8.0 depends on file: /usr/local/sbin/pkg - found ===> Fetching all distfiles required by sguil-sensor-0.8.0 for building ===> Extracting for sguil-sensor-0.8.0 => SHA256 Checksum OK for sguil-sensor-0.8.0.tar.gz. ===> Patching for sguil-sensor-0.8.0 ===> Applying FreeBSD patches for sguil-sensor-0.8.0 ===> Configuring for sguil-sensor-0.8.0 ===> Staging for sguil-sensor-0.8.0 ===> sguil-sensor-0.8.0 depends on package: tcltls>=0 - found ===> sguil-sensor-0.8.0 depends on executable: barnyard2 - found ===> sguil-sensor-0.8.0 depends on file: /usr/local/lib/tclx8.4/tclx.tcl - found ===> Generating temporary packing list (cd /obj/buildshare/ports/355755/security/sguil-sensor/work/sguil-0.8.0/sensor/contrib && /bin/sh -c '(/usr/bin/find -d $0 $2 | /usr/bin/cpio -dumpl $1 >/dev/null 2>&1) && /usr/sbin/chown -Rh root:wheel $1 && /usr/bin/find -d $0 $2 -type d -exec chmod 755 $1/{} \; && /usr/bin/find -d $0 $2 -type f -exec chmod 444 $1/{} \;' -- \* /obj/buildshare/ports/355755/security/sguil-sensor/work/stage/usr/local/share/sguil-sensor/contrib "! -name ossec_agent.tcl.orig") (cd /obj/buildshare/ports/355755/security/sguil-sensor/work/sguil-0.8.0/sensor/init && /bin/sh -c '(/usr/bin/find -d $0 $2 | /usr/bin/cpio -dumpl $1 >/dev/null 2>&1) && /usr/sbin/chown -Rh root:wheel $1 && /usr/bin/find -d $0 $2 -type d -exec chmod 755 $1/{} \; && /usr/bin/find -d $0 $2 -type f -exec chmod 444 $1/{} \;' -- \* /obj/buildshare/ports/355755/security/sguil-sensor/work/stage/usr/local/share/sguil-sensor/init) install -o root -g wheel -m 444 /obj/buildshare/ports/355755/security/sguil-sensor/work/sguil-0.8.0/README /obj/buildshare/ports/355755/security/sguil-sensor/work/stage/usr/local/share/doc/sguil-sensor install -o root -g wheel -m 444 /obj/buildshare/ports/355755/security/sguil-sensor/work/sguil-0.8.0/sensor/README.daemonlogger /obj/buildshare/ports/355755/security/sguil-sensor/work/stage/usr/local/share/doc/sguil-sensor install -o root -g wheel -m 444 /obj/buildshare/ports/355755/security/sguil-sensor/work/sguil-0.8.0/doc/CHANGES /obj/buildshare/ports/355755/security/sguil-sensor/work/sguil-0.8.0/doc/FAQ /obj/buildshare/ports/355755/security/sguil-sensor/work/sguil-0.8.0/doc/INSTALL /obj/buildshare/ports/355755/security/sguil-sensor/work/sguil-0.8.0/doc/INSTALL.openbsd /obj/buildshare/ports/355755/security/sguil-sensor/work/sguil-0.8.0/doc/OPENSSL.README /obj/buildshare/ports/355755/security/sguil-sensor/work/sguil-0.8.0/doc/TODO /obj/buildshare/ports/355755/security/sguil-sensor/work/sguil-0.8.0/doc/UPGRADE /obj/buildshare/ports/355755/security/sguil-sensor/work/sguil-0.8.0/doc/USAGE /obj/buildshare/ports/355755/security/sguil-sensor/work/sguil-0.8.0/doc/sguildb.dia /obj/buildshare/ports/355755/security/sguil-sensor/work/stage/usr/local/share/doc/sguil-sensor install -o root -g wheel -m 555 -m 751 /obj/buildshare/ports/355755/security/sguil-sensor/work/sguil-0.8.0/sensor/pcap_agent.tcl /obj/buildshare/ports/355755/security/sguil-sensor/work/stage/usr/local/bin/sguil-sensor/pcap_agent.tcl install -o root -g wheel -m 555 -m 751 /obj/buildshare/ports/355755/security/sguil-sensor/work/sguil-0.8.0/sensor/snort_agent.tcl /obj/buildshare/ports/355755/security/sguil-sensor/work/stage/usr/local/bin/sguil-sensor/snort_agent.tcl install -o root -g wheel -m 555 -m 751 /obj/buildshare/ports/355755/security/sguil-sensor/work/sguil-0.8.0/sensor/log_packets-daemonlogger.sh /obj/buildshare/ports/355755/security/sguil-sensor/work/stage/usr/local/bin/sguil-sensor/log_packets-daemonlogger.sh install -o root -g wheel -m 555 -m 751 /obj/buildshare/ports/355755/security/sguil-sensor/work/sguil-0.8.0/sensor/log_packets.sh /obj/buildshare/ports/355755/security/sguil-sensor/work/stage/usr/local/bin/sguil-sensor/log_packets.sh install -o root -g wheel -m 444 /obj/buildshare/ports/355755/security/sguil-sensor/work/sguil-0.8.0/sensor/pcap_agent.conf /obj/buildshare/ports/355755/security/sguil-sensor/work/stage/usr/local/etc/sguil-sensor/pcap_agent.conf-sample install -o root -g wheel -m 444 /obj/buildshare/ports/355755/security/sguil-sensor/work/sguil-0.8.0/sensor/snort_agent.conf /obj/buildshare/ports/355755/security/sguil-sensor/work/stage/usr/local/etc/sguil-sensor/snort_agent.conf-sample ====> Compressing man pages (compress-man) ===> Staging rc.d startup script(s) ===> Installing for sguil-sensor-0.8.0 ===> Checking if security/sguil-sensor already installed ===> Registering installation for sguil-sensor-0.8.0 Installing sguil-sensor-0.8.0... done *********************************** * !!!!!!!!!!! WARNING !!!!!!!!!!! * *********************************** If you already had barnyard2 installed, this port will NOT deinstall it and install the barnyard2-sguil port instead. You will need to deinstall the barnyard2 port and install the barnyard2-sguil port yourself instead. This port WILL NOT WORK without the barnyard2-sguil port!! See the /usr/local/share/doc/sguil-sensor/INSTALL doc for details on the configuration and for croning the script. WARNING!!! Sguil et al will fill up your /tmp directory very quickly. You should probably configure sguil et al to log to another partition/location (e.g. /nsm/tmp/). You must ALSO edit all of the sensor conf files (located in /usr/local/sguil-sensor/etc/) to reflect your configuration before starting the sensor_agents. A number of ancilliary things have been installed in /usr/local/share/sguil-sensor. If you chose to run sancp, and you already had a sancp.conf file in /usr/local/etc, copy it to sancp.conf.orig before creating the new one. The new sancp.conf-sample file contains the settings for squil. NOTE: the conf file is for sancp 1.5.3. It may need additional edits to work with the current ports version of sancp. If you still want to maintain the customized sancp.conf file, then copy the new sancp.conf-sample file to sguild-sancp.conf (for example) and add sancp_conf=/usr/local/etc/sguild-sancp.conf to /etc/rc.conf. Make package ===> Building package for sguil-sensor-0.8.0 slot1: removed