Snort mailing list archives

Re: Errors that don't cause problems / Problems without error message


From: Chris Green <cmg () sourcefire com>
Date: Tue, 09 Jul 2002 08:07:49 -0400

kai.hanisch () philips com writes:

Hi there,

I have snort 1.8.6 running on debian woody with 2.4.19pre9, and snort is 
behaving strange. In syslog it says:

FATAL ERROR: ERROR: Unable to open rules file:$PATH/snort.conf or 
$PATH//$PATH/snort.conf

Are you running this process chrooted? sounds like you are hupping
it.  Going to have to make that work again and probably revert to
ancient semantics for config files..

which cannot be true as snort runs and logging works fine. The error 
occurs every morning when cron.daily is running.

This is just a matter of interest, but what really disturbs me is that 
portscans are not being logged. Though /var/log/snort/portscan.log is 
created, nothing is logged there (Configuration in snort.conf says: 
"preprocessor portscan: $HOME_NET 4 3 portscan.log"). I have 644 
permissions on alert and portscan.log, owner ist root:snort.

Any help would be greatly appreciated.

Kai

-- 
Chris Green <cmg () sourcefire com>
A good pun is its own reword.


-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Stuff, things, and much much more.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: