Snort mailing list archives

Need help with snort packet logging


From: Ľubomír Bielik via Snort-users <snort-users () lists snort org>
Date: Fri, 27 Jul 2018 13:02:22 +0200

Hello community,

I have installed Snort3, and I am trying to use its packet logging feature,
but I'm not sure if I' doing everything right. I have installed it from the
manual on Snort website, without extra plugins, and then I tried to start
it with command "snort -dev -l ./log" from user manual.

I got this error:
ERROR: can't set -d ev
ERROR: usage: -d dump the Application Layer
FATAL: see prior 2 errors
Fatal Error, Quitting..


So I tried it with "snort -d -e -v -l./log", and all i got is only this:

--------------------------------------------------
o")~   Snort++ 3.0.0-245
--------------------------------------------------
--------------------------------------------------
pcap DAQ configured to passive.

Snort successfully validated the configuration (with 0 warnings).
o")~   Snort exiting


Then I even tried to specify interface, with "snort -d -e -v -i eth0 -l
./log". I got output while pinging Google DNS, but still nothing is being
saved to log folder. The folder is created and writeable, however I still
don't know what can be bad.
_______________________________________________
Snort-users mailing list
Snort-users () lists snort org
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

        To unsubscribe, send an email to:
        snort-users-leave () lists snort org

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Current thread: