Snort mailing list archives

Re: [Snort-user] ERROR: ./../rules/app-detect.rules(0) Unable to open rules file "./../rules/app-detect.rules": No such file or directory.


From: "Joel Esler (jesler)" <jesler () cisco com>
Date: Thu, 22 Jan 2015 21:45:30 +0000

If you go to Snort.org<http://Snort.org>, you will see a big red button on the left hand side that says “Rules”.  Click 
on that.


--
Joel Esler
Open Source Manager
Threat Intelligence Team Lead
Talos

On Jan 22, 2015, at 3:44 PM, zT <zzahra88 () gmail com<mailto:zzahra88 () gmail com>> wrote:

this is my paths
var RULE_PATH ../rules
var SO_RULE_PATH ../so_rules
var PREPROC_RULE_PATH ../preproc_rules

but in  /etc/snort/rules there is no file!!!! rules folder is empty i
try to download rules from snort.org<http://snort.org> but i can not find rules file in
that site

On 1/23/15, Steve Gantz <stephen.gantz () faculty umuc edu<mailto:stephen.gantz () faculty umuc edu>> wrote:
Check your RULE_PATH declaration in the step #1 section of snort.conf. You
can use an absolute path instead of a relative path if that is giving you
trouble - most installation guides have the rules in /etc/snort/rules but
you can put them elsewhere if you want. Just make sure the RULE_PATH
variable accurately points to the right rules directory.

Dr. Stephen D. Gantz, CISSP-ISSAP, CEH, CGEIT, CRISC, CIPP/G, C|CISO

Professor of Information Assurance

The Graduate School

University of Maryland University College

stephen.gantz () faculty umuc edu<mailto:stephen.gantz () faculty umuc edu>



On Jan 22, 2015, at 2:50 PM, zT <zzahra88 () gmail com> wrote:

hello, when i run this command
sudo snort -T -c snort.conf
i got this error
ERROR: ./../rules/app-detect.rules(0) Unable to open rules file
"./../rules/app-detect.rules": No such file or directory.
what i can do?

------------------------------------------------------------------------------
New Year. New Location. New Benefits. New Data Center in Ashburn, VA.
GigeNET is offering a free month of service with a new server in Ashburn.
Choose from 2 high performing configs, both with 100TB of bandwidth.
Higher redundancy.Lower latency.Increased capacity.Completely compliant.
http://p.sf.net/sfu/gigenet
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort
news!


------------------------------------------------------------------------------
New Year. New Location. New Benefits. New Data Center in Ashburn, VA.
GigeNET is offering a free month of service with a new server in Ashburn.
Choose from 2 high performing configs, both with 100TB of bandwidth.
Higher redundancy.Lower latency.Increased capacity.Completely compliant.
http://p.sf.net/sfu/gigenet
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

------------------------------------------------------------------------------
New Year. New Location. New Benefits. New Data Center in Ashburn, VA.
GigeNET is offering a free month of service with a new server in Ashburn.
Choose from 2 high performing configs, both with 100TB of bandwidth.
Higher redundancy.Lower latency.Increased capacity.Completely compliant.
http://p.sf.net/sfu/gigenet
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: