LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 03-23-2009, 02:15 AM   #1
priyadarshan
Member
 
Registered: Feb 2009
Location: Ahmedabad, Gujarat, India
Posts: 197

Rep: Reputation: Disabled
Question Snort


I am running snort in the IPS mode.....

I have just started by writing simple rule

alert tcp any any -> any any (msg:"Japan Dave"


But when I run the snort.conf by command

sudo snort -Qc /etc/snort/snort.conf -l /etc/snort

I get an error message saying:./rules/local.rules => Each rule must contain a Rule-id.

Last edited by priyadarshan; 03-23-2009 at 02:16 AM.
 
Old 03-23-2009, 01:24 PM   #2
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,137

Rep: Reputation: 7842Reputation: 7842Reputation: 7842Reputation: 7842Reputation: 7842Reputation: 7842Reputation: 7842Reputation: 7842Reputation: 7842Reputation: 7842Reputation: 7842
Quote:
Originally Posted by priyadarshan View Post
I am running snort in the IPS mode.....

I have just started by writing simple rule

alert tcp any any -> any any (msg:"Japan Dave"


But when I run the snort.conf by command

sudo snort -Qc /etc/snort/snort.conf -l /etc/snort

I get an error message saying:./rules/local.rules => Each rule must contain a Rule-id.
Right....so give the rule you added a Rule-ID header. Read the documentation.
 
Old 03-24-2009, 12:50 AM   #3
priyadarshan
Member
 
Registered: Feb 2009
Location: Ahmedabad, Gujarat, India
Posts: 197

Original Poster
Rep: Reputation: Disabled
I cant get you.... even I read socumentation twice throughly........ But the thing is that they too have specified rule in such way only.......

Is there anything new that I need to add in rule?
 
Old 03-24-2009, 10:17 AM   #4
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,137

Rep: Reputation: 7842Reputation: 7842Reputation: 7842Reputation: 7842Reputation: 7842Reputation: 7842Reputation: 7842Reputation: 7842Reputation: 7842Reputation: 7842Reputation: 7842
Quote:
Originally Posted by priyadarshan View Post
I cant get you.... even I read socumentation twice throughly........ But the thing is that they too have specified rule in such way only.......

Is there anything new that I need to add in rule?
Check this page http://www.snort.org/docs/snort_htma...3/node195.html for information on writing Snort rules.

Your error message says you need to give the rule an ID, which you haven't done. Give it one.
 
Old 03-25-2009, 12:39 AM   #5
priyadarshan
Member
 
Registered: Feb 2009
Location: Ahmedabad, Gujarat, India
Posts: 197

Original Poster
Rep: Reputation: Disabled
Thanks......
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[HELP]SNORT PROBLEMS(IDS)-service snort start JayCool Linux - Software 5 03-15-2009 12:34 PM
Snort - no portscan and tcp alerts in snort av.dubey Linux - Software 6 07-11-2008 09:56 PM
Starting snort: ERROR: User "snort" unknown games1 Linux - Software 3 02-07-2007 08:21 PM
Error when starting up snort: bash:!/bin/sh/usr/local/bin/snort :Eent not found cynthia_thomas Linux - Software 1 11-11-2005 02:59 PM
snort failed: snort: symbol lookup error: undefined symbol: usmAES192PrivProtocol Emmanuel_uk Linux - Security 1 07-10-2005 10:29 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 12:11 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration