Snort mailing list archives

Re: snort not running as service


From: Sadanand Ghagare <sadanandgh () gmail com>
Date: Mon, 25 Jan 2010 18:22:37 -0500

When I placed \ in third line which I forgot to enter, it started successfully.

preprocessor sfportscan: proto  { all } \
                         memcap { 10000000 } \
                         sense_level { low } \
                  logfile { portscan.log }


On Mon, Jan 25, 2010 at 5:42 PM, Sadanand Ghagare <sadanandgh () gmail com> wrote:
I was following step Configure WinIDS to run as a Service for winodws
sever 2003 with IIS 6 and MSSQL as per the steps on winsnort.com.
I can able to successfully add snort as service and make it Auto as
per the steps.
But when I restarted computer, snort service refused to start giving
follwing error:
The description for Event ID ( 1 ) in Source ( SnortService ) cannot
be found. The local computer may not have the necessary registry
information or message DLL files to display messages from a remote
computer. You may be able to use the /AUXSOURCE= flag to retrieve this
description; see Help and Support for details. The following
information is part of the event: e:\winids\snort\etc\snort.conf(514)
Unknown rule type: logfile.

Whether this error is anything to do with the follwoing line which I
have configured in snort .conf?
logfile { portscan.log }

--


Thanks & Regards

Sadanand G.




-- 


Thanks & Regards

Sadanand G.

------------------------------------------------------------------------------
The Planet: dedicated and managed hosting, cloud storage, colocation
Stay online with enterprise data centers and the best network in the business
Choose flexible plans and management services without long-term contracts
Personal 24x7 support from experience hosting pros just a phone call away.
http://p.sf.net/sfu/theplanet-com
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: