Snort mailing list archives

Re: so_rules issue


From: "Gibson, Nathan J. (HSC)" <Nathan-Gibson () ouhsc edu>
Date: Wed, 19 Jan 2011 21:03:28 -0600

Snort is assuming you in /etc/snort and automatically appending /etc/snort for you. So put this in your snort.conf.

So_rule_path=/so_rules

Or

So_rule_path=../so_rules

Cant remember but one of them should work.



From: Michael Lubinski [mailto:michael.lubinski () gmail com]
Sent: Wednesday, January 19, 2011 8:42 PM
To: snort-users () lists sourceforge net
Subject: [Snort-users] so_rules issue

My snort installation will not any so_rules files. If i comment out all of the so_rules files in the snort.conf it 
starts fine. I get this error:

Error: unable to open rules file "etc/snort//etc/snort/so_rules/bad-traffic.rules no such file or directory

I have enough smarts in me to see that that file path is jacked up. But i cannot find where it is double specifying the 
file path. My var so_rule_path = /etc/snort/so_rules

Any ideas?
------------------------------------------------------------------------------
Protect Your Site and Customers from Malware Attacks
Learn about various malware tactics and how to avoid them. Understand 
malware threats, the impact they can have on your business, and how you 
can protect your company and customers by using code signing.
http://p.sf.net/sfu/oracle-sfdevnl
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Current thread: