Snort mailing list archives

Re: ERROR LOG


From: <bthaler () webstream net>
Date: Thu, 18 Apr 2002 16:33:53 -0400

Looks like you forgot the ':' after the word 'flow' in your rule.

See http://www.snort.org/docs/writing_rules/chap2.html#tth_sEc2.3.36





Sincerely,

Brad T. 




----- Original Message ----- 
From: "Carlos Augusto Silva" <carlos () tvcultura com br>
To: <snort-users () lists sourceforge net>
Sent: Thursday, April 18, 2002 4:14 PM
Subject: [Snort-users] ERROR LOG


Hello,
I recept error message:

Apr 18 14:45:43 snort snort: Initializing daemon mode
Apr 18 14:45:43 snort snort: PID stat checked out ok, PID set to /var/run/
Apr 18 14:45:43 snort snort: Writing PID file to "/var/run/"
Apr 18 14:45:50 snort snort: FATAL ERROR:  ERROR:
/usr/local/snort/rules/experimental.rules(16) => Unknown keyword flow" in
rule!
Apr 18 14:45:51 snort kernel: device eth0 left promiscuous mode

How a starting my snort using rules configuration files ?
I using snort 1.8.6 and RedHat Linux 7.0

Tanks for all

Carlos
Brazil


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users



_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: