Snort mailing list archives

Re: New user to Snort . . .


From: Russ via Snort-users <snort-users () lists snort org>
Date: Tue, 16 Oct 2018 10:23:47 -0400

Adding to Joel's comment:

Linux is a much better choice for Snort IMO and the only way to get all the features since some are not supported on Windows.  It is also the only way to get Snort 3, which I recommend.  That said you could try WSL and many folks have successfully built and run Snort 2 on Windows.  Another plug for Snort 3: you get a suite of tests with configs and pcaps that demonstrate various features.  You can get it from snort.org or https://github.com/snort3.

On 10/16/18 10:14 AM, Joel Esler (jesler) via Snort-users wrote:
I would not recommend any books about Snort at this point, they are very out of date.  I'd stick to the manual and to the links on Snort.org/documents <http://Snort.org/documents>

On Oct 16, 2018, at 8:59 AM, David Adams JR via Snort-users <snort-users () lists snort org <mailto:snort-users () lists snort org>> wrote:

I am preparing for the CompTIA CyberSecurity Analyst+ exam and believe "hands on" is better than just text book memorizing.  Which is what I have done (hands on) over the years by purchasing hardware and software to create myself a very helpful lab.  I have eight switches, ten routers, six servers, W7, W10, WS2008, WS2012, and WS2016.  I have passed the CompTIA+ A+, Network+, Security+ and Server+ exams and also way back when, passed the Microsoft W95, W98, and the battery of exams required for the Microsoft Certified Systems Engineer certification for 4.0  . . . . just as Windows 2000 came out . . . .   by then I was unemployed and unable to afford the books and test fees . . . .

But eventually, I regained employment and resumed my self training.

So here I am "learning" about Snort . . .   but only 'book knowledge'.  So far my posts have resulted in links back to the Snort  'documents' which appear to be mostly links to forums and not the helpful PDF's I have come to find much more helpful.

I went to Amazon and googled "Snort" and there are several books to choose from.  I read the reviews and most were not too encouraging.

So what I am looking for is some sort of step-by-step guide or instructions on how to set up Snort on a Windows 2008 or 2012 server and how to test it to see if it really works.  I THINK that involves installing an Apache server on top of WS.  Or I can install Redhat Enterprise Linux 7.x - only I know so much less about Linux . . . .

Anyhow, if you can recommend a book from Amazon or another resource to assist me in getting going, I'd appreciate it.

Thank you for your time,

David JR

David M. Adams JR
4475 Barden Avenue
Mobile, Alabama  36619
dadamsjr () live com <mailto:dadamsjr () live com>
(678) 641-0572 <tel:%28678%29%20641-0572>(cell)

<Cisco Lab.png>_______________________________________________
Snort-users mailing list
Snort-users () lists snort org <mailto:Snort-users () lists snort org>
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

To unsubscribe, send an email to:
snort-users-leave () lists snort org <mailto:snort-users-leave () lists snort org>

Please visithttp://blog.snort.org <http://blog.snort.org/>to stay current on all the latest Snort news!

Please follow these rules:https://snort.org/faq/what-is-the-mailing-list-etiquette



_______________________________________________
Snort-users mailing list
Snort-users () lists snort org
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

        To unsubscribe, send an email to:
        snort-users-leave () lists snort org

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

_______________________________________________
Snort-users mailing list
Snort-users () lists snort org
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

        To unsubscribe, send an email to:
        snort-users-leave () lists snort org

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Current thread: