Snort mailing list archives

(no subject)


From: jcosta () lendleaserei com
Date: Thu, 27 Feb 2003 17:32:54 -0500

Using snort-1.9.0 and the rules it ships with placed into /etc/snort
directory (customized snort.conf files located there also).

I'm trying to get snort to push its alerts into syslog with the following
command line: snort -A fast -s -c /etc/snort/snort.conf

When I issue this command (which seems syntactically correct), I get the
following error:

Initializing Output Plugins!
Log directory = /var/log/snort

Initializing Network Interface eth1
ERROR: OpenPcap() FSM compilation failed:
        parse error
PCAP command: /etc/snort/snort.conf
Fatal Error, Quitting..


I realize that some of the command line args for snort are passed onto
libpcap which in this case
is complaining about a parse error.  The error looks like its choking on
the argument pointing my snort.conf file.

 What am I doing wrong here?

Jeff


Current thread: