Snort mailing list archives

Re: Any way to change permissions of the unified output files?


From: Bamm Visscher <bamm.visscher () gmail com>
Date: Wed, 25 May 2005 18:50:05 -0500

From ./snort --help

-m <umask> Set umask = <umask>

Bammkkkk


On 5/25/05, Rob Baxter <rbaxter () xapiens net> wrote:

The output files generated by the unified output plugin (ie the alert
and log files) always seem to be created with only rw permissions for
the root user. I need to collect the log files from a Solaris machine
which does not allow remote root logins. Is there any way to get snort
to set a different acl on the output files? I've tried using the -u
option to run snort as a different user but the files still get created
as root. I can whip up a cron job to periodically chown the files but
I'd prefer something less hackey.

</rob>


-- 
sguil - The Analyst Console for NSM
http://sguil.sf.net


-------------------------------------------------------
SF.Net email is sponsored by: GoToMeeting - the easiest way to collaborate
online with coworkers and clients while avoiding the high cost of travel and
communications. There is no equipment to buy and you can meet as often as
you want. Try it free.http://ads.osdn.com/?ad_idt02&alloc_id135&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: