LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 07-17-2009, 04:44 AM   #1
genmaicha
Member
 
Registered: Apr 2009
Posts: 38

Rep: Reputation: 15
snort installation from source


So I've downloaded snort-2.8.4.1.tar.gz snortrules-snapshot-2.8.tar.gz (the 'registered user' rules). I extracted snort-2.8.4.1.tar.gz. There's no INSTALL or README or any form of installation instruction in this archive (or the main snort.org website), but a ./configure && make && make install seems to install fine. What do I do with snortrules-snapshot-2.8.tar.gz? Do I extract directly to /usr/local (the ./configure prefix)? And how do I build the rules for my distro?

Last edited by genmaicha; 07-17-2009 at 04:47 AM.
 
Old 07-17-2009, 05:12 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by genmaicha View Post
There's no INSTALL or README or any form of installation instruction in this archive (or the main snort.org website),
If the tarball doesn't contain a doc/ dir and if snort.org didn't contain a docs/ dir that statement would be true.


Quote:
Originally Posted by genmaicha View Post
but a ./configure && make && make install seems to install fine.
Running './configure --help' gets you a listing of the available options. No need to come back later to say it doesn't work if you didn't bother to read and compile needed options.


Quote:
Originally Posted by genmaicha View Post
What do I do with snortrules-snapshot-2.8.tar.gz? Do I extract directly to /usr/local (the ./configure prefix)?
That depends on your snort.conf settings but usually rules go in /etc/snort/rules.


Quote:
Originally Posted by genmaicha View Post
And how do I build the rules for my distro?
You didn't list any: fill in your details in your control panel.
 
Old 07-17-2009, 01:54 PM   #3
genmaicha
Member
 
Registered: Apr 2009
Posts: 38

Original Poster
Rep: Reputation: 15
Okay, sorry, I should have looked closer. I've got snort installed on my slackware box and it runs fine the the packet sniffer mode. I copied the rules/ directory in the snortrules archive to /etc/snort/rules, edited the snort.conf file to reflect my changes, and it seems to be working (I see alerts in /var/log/snort). However, I'm still wondering what the so_rules directory is-- it contains precompiled libraries for other distros, but cannot figure out how to compile them or where to install them.
 
Old 07-18-2009, 06:11 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
http://vrt-sourcefire.blogspot.com/2...ect-rules.html ?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[HELP]SNORT PROBLEMS(IDS)-service snort start JayCool Linux - Software 5 03-15-2009 12:34 PM
LXer: Sourcefire's Roesch pledges long, open-source life for Snort LXer Syndicated Linux News 0 02-26-2006 08:01 PM
Strange installation results of Snort serverpimp Debian 3 11-01-2005 04:41 PM
snort installation not going well... rosey Linux - Software 1 09-16-2005 09:38 PM
Snort installation problems on slackware 10 scribbler001 Linux - Security 8 04-18-2005 12:09 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 05:03 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration