Snort mailing list archives

turn off some logging


From: Jonathan <rakocy () cs wisc edu>
Date: Sat, 24 May 2003 14:20:43 -0500 (CDT)

Hello,

I am currently running snort and would like to turn of logging to text
files on the local machine.  We have no use for this anymore as the
database setup does everything.  We log to the db and then pull the alerts
directly from there. 

In snort.conf i have the output plugin correct.  In the command line, if I
do not specify a directory to log to (-l /some/dir), snort obviously 
complains about not being able to log to /var/log/snort.  The only option
i could see was the -N which gives the same fatal error. I've tried -l
/dev/null also. 

here is my current command line. 
/bin/snort -d -i eth2 -c /etc/snort.conf -D

Running in IDS mode
Log directory = /var/log/snort
ERROR: 
[!] ERROR: Can not get write access to logging directory "/var/log/snort".
(directory doesn't exist or permissions are set incorrectly
or it is not a directory at all)

Fatal Error, Quitting..

Any suggestions would be great.

Thank you,

Jonathan Rakocy

 --CSL-- 
UW Madison




-------------------------------------------------------
This SF.net email is sponsored by: ObjectStore.
If flattening out C++ or Java code to make your application fit in a
relational database is painful, don't do it! Check out ObjectStore.
Now part of Progress Software. http://www.objectstore.net/sourceforge
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: