Snort mailing list archives

Re: Red Hat Enterprise Linux 6.5


From: Terry John <Terry.John () completeautomotivesolutions co uk>
Date: Wed, 4 Mar 2015 14:43:19 +0000

I’ve tried both ways. I would normally recommend the RPM route because it seemed it was more complete. Without being 
100% sure it seemed the RPM version had all the correct  SELinux settings as well as creating the correct user. The RPM 
does install to different directories but that’s no big thing.

Having said that, the last time I updated, the Centos 6.5 Snort RPM was no longer available and I had to compile the 
snort-2.9.7.0-1.src.rpm and  then do a yum update.

If I had to start again, I think I would follow Jeremy’s advice and compile snort from source. Whatever issues you 
discover, you’ll be ready for them next time.

Terry

From: Jeremy Hoel [mailto:jthoel () gmail com]
Sent: 03 March 2015 17:40
To: Farnsworth, Robert
Cc: snort-users () lists sourceforge net
Subject: Re: [Snort-users] Red Hat Enterprise Linux 6.5

In my opinion, you're probably better off building from source the things you'll need.  They will be more up to date 
and easier to replace/upgrade/tweak when the time comes, in addition to adding pfring if you need it.  A quick down and 
dirty looks like this:

yum Install the normal build tools

install tcpdump/libpcap from source

ldconifg

yum -y install mysql-devel zlib zlib-devel pcre pcre-devel

ldconfig

install dnet from source

ln -s /usr/local/lib/libdnet.1 /usr/lib/
ln -s /usr/local/lib/libdnet.1 /usr/lib64/

ldconfig

install daq from source

/usr/local/bin/daq-modules-config

ldconfig

install snort from source

Links
tcpdump/libpcap - http://www.tcpdump.org/#latest-release
libdnet - http://libdnet.sourceforge.net/
snort/daq - https://www.snort.org/downloads


On Tue, Mar 3, 2015 at 10:14 AM, Farnsworth, Robert <robert.farnsworth () hp com<mailto:robert.farnsworth () hp com>> 
wrote:
I am getting ready to install SNORT on Red Hat Enterprise Linux 6.5, I am a little confused on what packages need to be 
install with this version I am thinking the Fedora 18 is correct but am not sure.

And was trying to use the set-up guide for Fedora 17/18/19.

Can someone who knows respond. Am I headed in the right direction?

Thanks

Robert L. Farnsworth
Information Security Analyst
HP Enterprise Services
Telephone +1 248.639.6313<tel:%2B1%20248.639.6313>
Email robert.farnsworth () hp com<mailto:robert.farnsworth () hp com>


------------------------------------------------------------------------------
Dive into the World of Parallel Programming The Go Parallel Website, sponsored
by Intel and developed in partnership with Slashdot Media, is your hub for all
things parallel software development, from weekly thought leadership blogs to
news, videos, case studies, tutorials and more. Take a look and join the
conversation now. http://goparallel.sourceforge.net/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net<mailto:Snort-users () lists sourceforge net>
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!




The Manheim group of companies within the UK comprises: Manheim Europe Limited (registered number: 03183918), Manheim 
Auctions Limited (registered number: 00448761), Manheim Retail Services Limited (registered number: 02838588), 
Motors.co.uk Limited (registered number: 05975777), Real Time Communications Limited (registered number: 04277845) and 
Complete Automotive Solutions Limited (registered number: 05302535). Each of these companies is registered in England 
and Wales with the registered office address of Central House, Leeds Road, Rothwell, Leeds LS26 0JE. The Manheim group 
of companies operates under various brand/trading names including Manheim Inspection Services, Manheim Auctions, 
Manheim Direct, Manheim De-fleet and Manheim Aftersales Solutions.

V:0CF72C13B2AC


------------------------------------------------------------------------------
Dive into the World of Parallel Programming The Go Parallel Website, sponsored
by Intel and developed in partnership with Slashdot Media, is your hub for all
things parallel software development, from weekly thought leadership blogs to
news, videos, case studies, tutorials and more. Take a look and join the 
conversation now. http://goparallel.sourceforge.net/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: