Snort mailing list archives

Re: ERROR: can't find nfq DAQ


From: "Al Lewis (allewi)" <allewi () cisco com>
Date: Wed, 30 Nov 2016 19:59:53 +0000

The error is “ERROR: OpenAlertFile() => fopen() alert file /var/log/snort/alert: Permission denied"

Doesn’t look like snort can write to your logging directory.




Albert Lewis
ENGINEER.SOFTWARE ENGINEERING
SOURCEfire, Inc. now part of Cisco
Email: allewi () cisco com<mailto:allewi () cisco com>

From: Amal Saeed <amal.saeed () simmons edu<mailto:amal.saeed () simmons edu>>
Date: Wednesday, November 30, 2016 at 2:51 PM
To: 'snort-users' <snort-users () lists sourceforge net<mailto:snort-users () lists sourceforge net>>
Subject: [Snort-users] ERROR: can't find nfq DAQ

Hello,

I'm trying to run Snort in inline mode (-Q), but I kept running into this problem, where it says can't find nfq DAQ 
even though I see nfq listed in my --daq-list. I've tried troubleshooting with every source I found online, but now I 
get a different error.

If I run: snort --daq nfq -Q -c /etc/snort/snort.conf
I get:
Log directory = /var/log/snort
ERROR: OpenAlertFile() => fopen() alert file /var/log/snort/alert: Permission denied
Fatal Error, Quitting..

If I run: snort -T -c /etc/snort/snort.conf
I get:
[ Number of patterns truncated to 20 bytes: 497 ]
ERROR: Active response: can't open ip!
Fatal Error, Quitting..

I have an IP address and I can ping myself/others and receive pings with no issue.

Please advise on what I can do to resolve this, thank you!

--
Amal Saeed
Simmons College '17, B.S. Computer Science & Information Technology
Secretary, 2017 Class Council
Co-Vice President, Computer Science & Mathematics Liaison
Technology Assistant, Simmons Technology Support Center
------------------------------------------------------------------------------
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: