Snort mailing list archives

Re: SNORT GENERATING SNORT.LOG INSTEAD SNORT.U2 files


From: "Joel Esler (jesler)" <jesler () cisco com>
Date: Fri, 10 Jul 2015 12:18:45 +0000

-A on the command line overrides the snort.conf.

--
Joel Esler
Manager, Threat Intelligence and Open Source
Talos Group
Sent from my iPhone

On Jul 10, 2015, at 7:54 AM, Marcio Guerreiro <marcio.guerreiro () hotmail co uk<mailto:marcio.guerreiro () hotmail co 
uk>> wrote:


Waldo



You have just fixed the problem by asking me that question. My mistake !!! I was running snort with the –A console 
parameter :



snort  -Q -A console -u snort -g snort -c /etc/snort/snort.conf -i eth1:eth2



now I ran without the –A and it is working !!! thank you !!!



snort  -Q  -u snort -g snort -c /etc/snort/snort.conf -i eth1:eth2



<image001.png>













-----Original Message-----
From: waldo kitty [mailto:wkitty42 () windstream net]
Sent: 10 July 2015 11:48
To: snort-users () lists sourceforge net<mailto:snort-users () lists sourceforge net>
Subject: Re: [Snort-users] SNORT GENERATING SNORT.LOG INSTEAD SNORT.U2 files



On 07/10/2015 06:11 AM, Marcio Guerreiro wrote:

The problem is that the logs used to be generated as snort.u2 files,

but now is being generated as snort.log. I already checked the

snort.conf line 520  where the output format is specified and it is

correct (it hasn’t been changed)



My barnyard2 used to work and does not work anymore because it

supposed to look for those (snort.u2) files.



Any ideas ?



you haven't told us what your command line is or what your output settings are... no way to start guessing without 
those important pieces of information...



--

  NOTE: No off-list assistance is given without prior approval.

        *Please keep mailing list traffic on the list* unless

        private contact is specifically requested and granted.



------------------------------------------------------------------------------

Don't Limit Your Business. Reach for the Cloud.

GigeNET's Cloud Solutions provide you with the tools and support that you need to offload your IT needs and focus on 
growing your business.

Configured For All Businesses. Start Your Cloud Today.

https://www.gigenetcloud.com/

_______________________________________________

Snort-users mailing list

Snort-users () lists sourceforge net<mailto:Snort-users () lists sourceforge net>

Go to this URL to change user options or unsubscribe:

https://lists.sourceforge.net/lists/listinfo/snort-users

Snort-users list archive:

http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users



Please visit http://blog.snort.org to stay current on all the latest Snort news!

------------------------------------------------------------------------------
Don't Limit Your Business. Reach for the Cloud.
GigeNET's Cloud Solutions provide you with the tools and support that
you need to offload your IT needs and focus on growing your business.
Configured For All Businesses. Start Your Cloud Today.
https://www.gigenetcloud.com/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net<mailto:Snort-users () lists sourceforge net>
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

------------------------------------------------------------------------------
Don't Limit Your Business. Reach for the Cloud.
GigeNET's Cloud Solutions provide you with the tools and support that
you need to offload your IT needs and focus on growing your business.
Configured For All Businesses. Start Your Cloud Today.
https://www.gigenetcloud.com/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: