- To: Marty Richards <marty@xxxxxxxxxxxxxxxxxxxxx>
- Subject: RE: [SLUG] Troubles with SNORT
- From: Howard Lowndes <lannet@xxxxxxxxxxxxx>
- Date: Thu Jul 19 13:38:01 2001
- Cc: "'slug@xxxxxxxxxxx'" <slug@xxxxxxxxxxx>
I tried that and it didn't work, but I have since found the problem - the
config file needed to have the absolute paths to the rules files rather
than assuming relative paths.
--
Howard.
LANNet Computing Associates
Contact detail at http://www.lannetlinux.com
On Thu, 19 Jul 2001, Marty Richards wrote:
> Hi Howard,
>
> Tried commenting out the "include local.rules" entry in snort.conf?
>
> Cheers,
> Marty
>
> -----Original Message-----
> From: Howard Lowndes [mailto:lannet@xxxxxxxxxxxxx]
> Sent: Thursday, July 19, 2001 12:33 PM
> To: Mail List - SLUG
> Subject: [SLUG] Troubles with SNORT
>
>
> I am having problems getting SNORT started
>
> It complains that:
> Jul 19 12:22:31 gw snort: ERROR: Unable to open rules file: local.rules
>
> This file exists:
> -rw-r--r-- 1 snort snort 0 Apr 17 07:12
> /etc/snort/local.rules
>
> Admittedly it is zero length but I don't see that that should make a
> difference.
>
> Running strace on snort does not give any clue, in fact local.rules does
> not even get a guernsey.
>
> Pass the cluestick please.
>
>