Snort mailing list archives

problems in snort installing.


From: Mohammad MontazerI <mohamad_montazery () yahoo com>
Date: Sat, 16 Mar 2013 08:49:39 -0700 (PDT)

Hello.

i trying to install SNORT 2.9.4.1 and DAQ 2.0.0 in opensuse 12.2 on vmware.
i did it step by step according to the install guidewhich i downloaded from the main web site.

i will exactly write down there the commands which i used with their following messages:

linux-s211:/usr/sbin # ./snort -T -i eth0 -u snort -g snort -c /etc/snort/snort.conf
.
.
snort successfully validated the configuration!
Snort exiting

linux-s211:/usr/sbin # ./snort -i eth0 -D -u snort -g snort -c /etc/snort/snort.conf
Spawning daemon child...
My daemon child 3987 lives...
Daemon parent exiting (0)


inux-s211:/usr/sbin # ps aux | grep -i "snort"
snort     3987  0.1  5.4 316068 54936 ?        Ssl  11:59   0:00 ./snort -i eth0 -D -u snort -g snort -c /etc/s
root      3990  0.0  0.0   4172   804 pts/1    S+   11:59   0:00 grep --color=auto -i snort


everythings seems ok until here but!!:

linux-s211:/usr/sbin # /etc/init.d/snort start
bash: /etc/init.d/snort: Permission denied (i already switched to root and copied snort script to the /etc/init.d 
directory )

and this one: (i think this one is more important)

linux-s211:/usr/sbin # ./snort status
Running in packet dump mode
--== Initializing Snort ==--
Initializing Output Plugins!
Snort BPF option: status
pcap DAQ configured to passive.
Acquiring network traffic from "eth0".
ERROR: Can't set DAQ BPF filter to 'status' (pcap_daq_set_filter: pcap_compile: syntax error)! (i did install 
libdnet-devel-1.12-15.1.2.i586 and libpcap-devel-1.2.1-3.1.2.i586)
Fatal Error, Quitting..


now i really don't where i did wrong!  if you need more information about OS or anything else just say it.
please help me on it.
Thanks. 
------------------------------------------------------------------------------
Everyone hates slow websites. So do we.
Make your web apps faster with AppDynamics
Download AppDynamics Lite for free today:
http://p.sf.net/sfu/appdyn_d2d_mar
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: