Snort mailing list archives

Re: The DAQ version does not support reload


From: waldo kitty <wkitty42 () windstream net>
Date: Fri, 03 Oct 2014 13:33:09 -0400

On 10/3/2014 9:57 AM, Deepak Yadav wrote:
Hi all,


I have manage to install Snort on win7, i have ONE eth on my PC, and that one.i
am getting below error:

Please suggest..!!!

the subject title and reported error is not your problem...

C:\Snort\bin>snort -i 1 -e c:snort\etcsnort.conf -A console -T
Running in packet dump mode

         --== Initializing Snort ==--
Initializing Output Plugins!
Snort BPF option: c:snort\etcsnort.conf -A console -T

the above line is your problem...

pcap DAQ configured to passive.
The DAQ version does not support reload.
Acquiring network traffic from "\Device\NPF_{037B06CB-66F4-4AA9-AB91-9141848D1EAD}".
ERROR: Can't set DAQ BPF filter to 'c:snort\etcsnort.conf -A console -T' (└$O)!

which is further confirmed by the above line...

the solution is to use the proper command line options and parameters in the 
correct order...

-- 
  NOTE: No off-list assistance is given without prior approval.
        Please *keep mailing list traffic on the list* unless
        private contact is specifically requested and granted.

------------------------------------------------------------------------------
Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer
http://pubads.g.doubleclick.net/gampad/clk?id=154622311&iu=/4140/ostg.clktrk
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: