[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[suse-security] Problems with snort and Suse 9.1

Hi, everybody!

I tried to get snort run on Suse 9.1 for several days. A 'rcsnort 
restart' command has an output in /var/log/messages: snort 
initialization completed succesfully. But there is no logging of 
portscans, when I proof the program (doing it with www.heise.de). With 
Suse 9.0, I got lots of alerts, when I visit this site. A 'snort -T 
snort.conf' has this output:

stargate:/etc/snort # snort -T snort.conf
Running in IDS mode with inferred config file: ./snort.conf
Log directory = /var/log/snort

Initializing Network Interface eth0
ERROR: OpenPcap() FSM compilation failed:
        syntax error
PCAP command: snort.conf
Fatal Error, Quitting..

I used the original conf-file and also changed files, but in every case 
it has the same output. Looking for help with google or the list 
archive did not have a match. I hope, anybody at the list has a hint.


Klaus Niedt 

Check the headers for your unsubscription address
For additional commands, e-mail: suse-security-help@xxxxxxxx
Security-related bug reports go to security@xxxxxxx, not here