Snort mailing list archives

Problem after snort upgrade


From: "Le Pesant, Pascal" <plepesant () eonmediainc com>
Date: Tue, 1 Feb 2005 15:17:03 -0500

After upgrading snort to 2.3.0 (was 2.1.x):

I get the following error when starting snort:

# snort -c /etc/snort/snort.conf
Running in IDS mode

Initializing Network Interface eth0

        --== Initializing Snort ==--
Initializing Output Plugins!
Decoding Ethernet on interface eth0
Initializing Preprocessors!
Initializing Plug-ins!
Parsing Rules file /etc/snort/snort.conf

+++++++++++++++++++++++++++++++++++++++++++++++++++
Initializing rule chains...
ERROR: /etc/snort/snort.conf(43) => NULL rule type
Fatal Error, Quitting..

Also, I am relatively new in the linux world, and I want to know if I
used the right way to make the upgrade.
I did the snort install by following Patrick Harper's Snort Install
Manual on RH9.0 with snort 2.1.3 with Apache, PHP, MySQl and ACID.

Today I upgraded to 2.3.0 doing the following steps:
Backup /etc/snort/
# gzip-d -d -c snort-2.3.0.tar.gz | tar xvf -
# ./configure
# make
# make install

Copy new *.rules, *.conf, *.config, *.map to /etc/snort/
Re-customize new snort.conf based on the old one.

Do I need to do more steps to finish the upgrade ? If yes can it be the
reason why I have the previously explained error ? Thanks !

PLP


-------------------------------------------------------
This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting
Tool for open source databases. Create drag-&-drop reports. Save time
by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc.
Download a FREE copy at http://www.intelliview.com/go/osdn_nl
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: