Snort mailing list archives

RE: SNORT 2.3.0 Logging to Windows XP event logs


From: "Michael Steele" <michaels () winsnort com>
Date: Tue, 4 Jan 2005 16:36:46 -0800

Well, that is all well and almost proper but how does Snort find the log
folder?

An example:

Create a log folder: c:\snort\logs

Run snort: c:\snort\snort.exe -c c:\snort\etc\snort.conf -l c:\snort\logs

The above is only an example, but will work if Snort is detecting your
interface.

Kindest regards, 
Michael...

WINSNORT.com Management Team Member
-- 
Pick up your FREE Windows or UNIX Snort installation guides       
mailto:support () winsnort com
Website: http://www.winsnort.com
Snort: Open Source Network IDS - http://www.snort.org


-----Original Message-----
From: snort-users-admin () lists sourceforge net [mailto:snort-users-
admin () lists sourceforge net] On Behalf Of Rich Adamson
Sent: Tuesday, January 04, 2005 12:48 AM
To: Senthil Prabu.S; Adrian Farrell; snort-users () lists sourceforge net
Subject: Re: [Snort-users] SNORT 2.3.0 Logging to Windows XP event logs


snort -E -c c:\snort\etc\snort.conf
I am get the following error message:
Can not get write access to logging directory "log". (dorectory doesn't
exist or permissions
are set incorrectly or it is not a directory at all)
Hi,
    It means,you have not created the /var/log/snort directory. This
directory should be
created before starting snort.
So that all log and alerts get stored there for your reference.

Does anyone know why this is happening...am I doing something wrong or
do I need to change a
setting.

Just create the /var/log/snort directory. Check for it's permissions.
Now start your snort. It will work fine.


Or, better yet since this is a Windows box, how about creating
c:\snort\log directory

:)




-------------------------------------------------------
The SF.Net email is sponsored by: Beat the post-holiday blues
Get a FREE limited edition SourceForge.net t-shirt from ThinkGeek.
It's fun and FREE -- well, almost....http://www.thinkgeek.com/sfshirt
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users







-------------------------------------------------------
The SF.Net email is sponsored by: Beat the post-holiday blues
Get a FREE limited edition SourceForge.net t-shirt from ThinkGeek.
It's fun and FREE -- well, almost....http://www.thinkgeek.com/sfshirt
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: