Snort mailing list archives

snort 2.0 run error


From: "Semerjian, Ohanes" <ohanes.semerjian () au mci com>
Date: Mon, 26 May 2003 11:01:20 +0800

Dear all,

I've upgraded 7 sensors from 1.8.7 to 2.0 and they all working okay and
logging to the mysql database except for the last one...? they all have the
same config (I mean snort.conf). I'm runnining Solaris 8 on Sparc hardware.
The error I'm getting is below, couldn't find any artical on snort page or
anywhere else as the error not distinctive 

Initializing Network Interface hme1

        --== Initializing Snort ==--
Decoding Ethernet on interface hme1
Initializing Preprocessors!
Initializing Plug-ins!
Initializating Output Plugins!
Parsing Rules file snort.conf

+++++++++++++++++++++++++++++++++++++++++++++++++++
Initializing rule chains...
No arguments to frag2 directive, setting defaults to:
    Fragment timeout: 60 seconds
    Fragment memory cap: 4194304 bytes
Stream4 config:
    Stateful inspection: ACTIVE
    Session statistics: INACTIVE
    Session timeout: 30 seconds
    Session memory cap: 8388608 bytes
    State alerts: INACTIVE
    Scan alerts: ACTIVE
    Log Flushed Streams: INACTIVE
No arguments to stream4_reassemble, setting defaults:
     Reassemble client: ACTIVE
     Reassemble server: INACTIVE
     Reassemble ports: 21 23 25 53 80 143 110 111 513
     Reassembly alerts: ACTIVE
     Reassembly method: FAVOR_OLD
database: compiled support for ( mysql )
database: configured to use mysql
database:          user = xxxxx
database: password is set
database: database name = xxxxxxx
database:          host = a.b.c.d
database:   sensor name = 0.0.0.0
database:     sensor id = 3
database: schema version = 106
database: using the "log" facility
database: compiled support for ( mysql )
database: configured to use mysql
database:          user = xxxx
database: password is set
database: database name = xxxxx
database:          host = a.b.c.d
database:   sensor name = 0.0.0.0
database:     sensor id = 3
database: schema version = 106
database: using the "alert" facility
Error: Unknown config: reference
Fatal Error, Quitting..


Any assistance is much apprecaited.


Best Regards

Ohanes Semerjian


Current thread: