Snort mailing list archives

Re: DPX starter kit output: No alert generated


From: wkitty42--- via Snort-users <snort-users () lists snort org>
Date: Wed, 17 Oct 2018 16:22:22 -0400

On 10/17/18 4:07 PM, Jianyu Li via Snort-users wrote:
I followed the link below to build DPX.
https://www.snort.org/documents/dpx-readme

But there is no alert generated in the output of ./test.sh

I am using snort-2.9.12, daq-2.0.6, ubuntu 18.04.1 LTS on VirtualBox.


i don't know anything about dpx but what are the four short rules and what traffic was sent to be analyzed? the output looks to have passed the traffic... it may be that you need to add "-k none" to your snort command line to ensure that checksums are ignored...


--
 NOTE: No off-list assistance is given without prior approval.
       *Please keep mailing list traffic on the list unless*
       *a signed and pre-paid contract is in effect with us.*
_______________________________________________
Snort-users mailing list
Snort-users () lists snort org
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

        To unsubscribe, send an email to:
        snort-users-leave () lists snort org

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette


Current thread: