Snort mailing list archives

Re: Snort Command Line Options


From: Joe Brown <joeb1kenobe () gmail com>
Date: Wed, 18 May 2011 10:19:34 -0400

Thanks.  It does look like it is running now. Silly little mistakes make 
things appear harder.

Joe
On 05/18/2011 10:17 AM, Martin Holste wrote:
Sorry, I meant, try changing that and see if it makes a difference.

On Wed, May 18, 2011 at 9:16 AM, Martin Holste<mcholste () gmail com>  wrote:
Looks like you have an M dash (double-dash) there for -D (should be a
single dash).  Does that make a difference?

On Wed, May 18, 2011 at 8:51 AM, Joe Brown<joeb1kenobe () gmail com>  wrote:
I am a newbie to snort.

I am trying to use snort to send syslog to a remote server. In the
snort.conf, I have added:

_syslog: host=<ipAddress>:514, LOG_AUTH LOG_ALERT

I started snort with this command line:

/usr/local/bin/snort -s -i br0 -u snort -g snort -c /etc/snort/snort.conf –D

I get this error when snort starts:

Initializing Network Interface br0
OpenPcap() device br0 network lookup: br0: no IPv4 address assigned.
ERROR: Bpf compilation failed: illegal char '.'. PCAP filter: .D.
Fatal Error, Quitting..

When I do not use the -s option, snort start fine.

Does the -s options require a certain placement in the command line? Or
am I doing something totally wrong?

Joe Brown

------------------------------------------------------------------------------
What Every C/C++ and Fortran developer Should Know!
Read this article and learn how Intel has extended the reach of its
next-generation tools to help Windows* and Linux* C/C++ and Fortran
developers boost performance applications - including clusters.
http://p.sf.net/sfu/intel-dev2devmay
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users



------------------------------------------------------------------------------
What Every C/C++ and Fortran developer Should Know!
Read this article and learn how Intel has extended the reach of its 
next-generation tools to help Windows* and Linux* C/C++ and Fortran 
developers boost performance applications - including clusters. 
http://p.sf.net/sfu/intel-dev2devmay
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: