edit from the scratch
I have a problem trying to verify whether or not a rule is working when I'm using a .pcap file.
for example if I use this rule:
Code:
alert tcp any any <> any any (msg:"TEST";rev:1;sid:112321312;)
every packet should raise an alert, however when I load a pcap file I don't see these alerts.
If instead of loading a pcap file, I just run Snort and then dynamically generate traffic, the messages appear in /var/log/snort/alerts.
What am I missing?