LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 05-23-2005, 01:18 PM   #1
Atrocity
Member
 
Registered: Nov 2002
Location: Hell
Distribution: FreeBSD, Slackware
Posts: 308

Rep: Reputation: 30
Snort help


I have never used snort before and I just installed it on my slackware box. I am having trouble finding the install directory. I read somewhere that it would be in /etc/snort for configuration items but this directory does not exist! I ran the comany snort -dev and snort started running showing info so I know snort is working....

Questions:
1: where are the key directorys in slackware 10.1 for snort configuration and logging??
2: Places to get some good rulesets for snort since i heard the default flags to many errors??
3.: Any other info you can give me that you think may help is appreaciated???
 
Old 05-24-2005, 10:38 AM   #2
Atrocity
Member
 
Registered: Nov 2002
Location: Hell
Distribution: FreeBSD, Slackware
Posts: 308

Original Poster
Rep: Reputation: 30
Anyone????
 
Old 05-24-2005, 10:41 AM   #3
gbonvehi
Senior Member
 
Registered: Jun 2004
Location: Argentina (SR, LP)
Distribution: Slackware
Posts: 3,145

Rep: Reputation: 53
I've never used Snort.
1) Did you try /usr/local/etc ? Try using slocate or find to locate them.
2 and 3) don't know
 
Old 05-24-2005, 10:44 AM   #4
Atrocity
Member
 
Registered: Nov 2002
Location: Hell
Distribution: FreeBSD, Slackware
Posts: 308

Original Poster
Rep: Reputation: 30
slocate seemst to only find the files in the directory that I unzipped and installed it from?

and find snort just says "no such file or directory"
 
Old 05-24-2005, 10:52 AM   #5
gbonvehi
Senior Member
 
Registered: Jun 2004
Location: Argentina (SR, LP)
Distribution: Slackware
Posts: 3,145

Rep: Reputation: 53
Code:
find / -name 'snort*'
Acording to a doc i found, you should have a sample configuration file at /usr/local/etc called snort.conf-sample (this can vary if you used the --prefix argument when compiling).

Edit: This config sample file should also come with the sources of snort, so simply getting it from there and copying to the directory where snort tries to read it, should work.

Last edited by gbonvehi; 05-24-2005 at 10:56 AM.
 
Old 05-24-2005, 10:54 AM   #6
Atrocity
Member
 
Registered: Nov 2002
Location: Hell
Distribution: FreeBSD, Slackware
Posts: 308

Original Poster
Rep: Reputation: 30
Interesting, the only files found with both of those comands are the files from the install, Do I have to create the folders in etc and wherever else that run snort from scratch??? Does anyone know?


Thanks for the find commands!!!!!!!!!!
 
Old 05-24-2005, 10:57 AM   #7
gbonvehi
Senior Member
 
Registered: Jun 2004
Location: Argentina (SR, LP)
Distribution: Slackware
Posts: 3,145

Rep: Reputation: 53
Ermm, did you installed snort? If you did, how?

The easy way:http://www.linuxpackages.net/search_...snort&ver=10.1
 
Old 05-24-2005, 11:00 AM   #8
Atrocity
Member
 
Registered: Nov 2002
Location: Hell
Distribution: FreeBSD, Slackware
Posts: 308

Original Poster
Rep: Reputation: 30
I installed snort from the package I got from snort.org and I used
./configure
make
make install

I recieved no errors and if I type snort -dev into the prompt snort will start scrolling network traffic so I know its installed
 
Old 05-24-2005, 11:14 AM   #9
gbonvehi
Senior Member
 
Registered: Jun 2004
Location: Argentina (SR, LP)
Distribution: Slackware
Posts: 3,145

Rep: Reputation: 53
I downloaded snort source and I see a etc directory inside it with snort.conf file, you may want to check it. You could try creating a snort directory inside /etc with: mkdir /etc/snort and copying that config file there.

Last edited by gbonvehi; 05-24-2005 at 11:16 AM.
 
Old 05-24-2005, 11:17 AM   #10
Atrocity
Member
 
Registered: Nov 2002
Location: Hell
Distribution: FreeBSD, Slackware
Posts: 308

Original Poster
Rep: Reputation: 30
Sweeeet , thanks I didnt know you would have to use the instalation files for the directory your configs are in, all the tutorials indicate that the files would be in the /etc /snort directory of the root filesystem....

Thanks for you help!!!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Error when starting up snort: bash:!/bin/sh/usr/local/bin/snort :Eent not found cynthia_thomas Linux - Software 1 11-11-2005 02:59 PM
Snort It Up metallica1973 Linux - Security 1 08-17-2005 11:33 AM
snort failed: snort: symbol lookup error: undefined symbol: usmAES192PrivProtocol Emmanuel_uk Linux - Security 1 07-10-2005 10:29 AM
Snort juanb Linux - Software 0 03-19-2003 06:22 AM
snort snort.conf help crealkiller175 Linux - Software 1 03-08-2003 05:58 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 11:39 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration