Snort mailing list archives

snort.conf problem: i think


From: "Kevin Moker" <kevin.moker () snet net>
Date: Fri, 25 Jan 2002 15:16:45 -0500

Can someone tell me what I am doing wrong?  I am running snort on win2k (yeah, I know, that's my first mistake) and 
need to figure out why the following error is coming up.  I am new to snort and I am having some difficulties with it.

Here is the error:

C:\snort>snort -dev -l c:\inetpub\wwwroot\Logs -h 10.0.0.13/24 -c snort.conf

        --== Initializing Snort ==--

Initializing Network Interface \Device\Packet_{A4B3B48F-2737-45FB-82D6-D79E5EA5C55D}
Decoding Ethernet on interface \Device\Packet_{A4B3B48F-2737-45FB-82D6-D79E5EA5C55D}
Initializing Preprocessors!
Initializing Plug-ins!
Initializating Output Plugins!

+++++++++++++++++++++++++++++++++++++++++++++++++++
Initializing rule chains...

*WARNING*: unknown preprocessor "frag2", ignoring!


*WARNING*: unknown preprocessor "stream4", ignoring!


*WARNING*: unknown preprocessor "stream4_reassemble", ignoring!


*WARNING*: unknown preprocessor "rpc_decode", ignoring!


*WARNING*: unknown preprocessor "bo", ignoring!


*WARNING*: unknown preprocessor "telnet_decode", ignoring!

Using LOCAL time
Error: Unknown config: classification

This command works:

C:\snort>snort -dev -l c:\inetpub\wwwroot\Logs -h 10.0.0.13/24

        --== Initializing Snort ==--

Initializing Network Interface \Device\Packet_{A4B3B48F-2737-45FB-82D6-D79E5EA5C55D}
Decoding Ethernet on interface \Device\Packet_{A4B3B48F-2737-45FB-82D6-D79E5EA5C55D}

        --== Initialization Complete ==--

-*> Snort! <*-
Version 1.7-WIN32
By Martin Roesch (roesch () clark net, www.snort.org)
WIN32 Port By Michael Davis (mike () datanerds net, www.datanerds.net/~mike)

This is why I think it's the conf file but I don't have enough knowledge yet on this. Can someone help?

Current thread: