You are not logged in.
Hey guys,
I'm trying to get snort working on my middle box... When I try and run start snort (/etc/rc.d/snort start), it would fail and give me no output. So for debugging purposes, I looked at the rc script and figured out it was running this command.
[wsduvall@Sebek ~]$ snort -l /var/log/snort -K ascii -c /etc/snort/snort.conf -A full -b -D -p -u snort -g snort -i eth0 -c /etc/snort/snort.conf
ERROR: log directory '/var/log/snort' does not exist
Fatal Error, Quitting..
[wsduvall@Sebek ~]$
It claims that /var/log/snort does not exist. But it does...
[wsduvall@Sebek ~]$ ls -l /var/log/
...
drwxr-xr-x 2 snort snort 4096 Feb 12 15:53 snort
...
Anybody got any ideas?
My 5 node 9 CPU cluster: www.amenrecluster.com
OS: Arch Linux
Machines:Fujitsu T4210 and IBM eServer xSeries 335
Offline
Try running snort as root or with sudo? Don't know if you actually need to, but try it.
Also try changing the permissions on /var/log/snort/ to allow group and other to write as well and see if maybe you have a permissions problem.
Offline
Hmm this is weird... it seems to work when I use sudo, but when I try the rc.d scrip as sudo, it doesn't work...
My 5 node 9 CPU cluster: www.amenrecluster.com
OS: Arch Linux
Machines:Fujitsu T4210 and IBM eServer xSeries 335
Offline
Check the permissions on the /etc/rc.d script as well as possibly taking a look at the contents of /etc/snort.conf. Again, I don't know much about snort but check these out and see if it leads you anywhere.
Offline