Snort mailing list archives

Re: startup error on with blacklist rules


From: Joel Esler <jesler () sourcefire com>
Date: Mon, 11 Mar 2013 11:36:50 -0400

On Mar 11, 2013, at 10:11 AM, Jim Turner <JTurner () hilltopconsultants com> wrote:

Hello Everyone,
 
I got past the problem I reported the other day.  However, now I am stuck on a different error processing blacklist 
and most likely whitelist rules.
 
I have attached my snort.conf and the error that I am receiving.
 
I am running 2.9.4.1 on Windows 7 Pro.  I really appreciate your help.
 

Doesn't look like the error has anything to do with blacklist rules.  Looks like you aren't including your 
classification.config in your snort.conf, and therefore Snort isn't able to parse app-detect.rules because Snort can't 
find the correct classifications.

--
Joel Esler
Senior Research Engineer, VRT
OpenSource Community Manager
Sourcefire
------------------------------------------------------------------------------
Symantec Endpoint Protection 12 positioned as A LEADER in The Forrester  
Wave(TM): Endpoint Security, Q1 2013 and "remains a good choice" in the  
endpoint security space. For insight on selecting the right partner to 
tackle endpoint security challenges, access the full report. 
http://p.sf.net/sfu/symantec-dev2dev
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: