Can't read data_log output file (empty)

Ronin CS via Snort-devel <[email protected]>
Newsgroups gmane.comp.security.ids.snort.devel
Message-ID <CADvVe_6BbSkvBP8MHwNzqUHa2KKe4SRJtWo=CmY2Uyht3UM=xw@mail.gmail.com>
Hello everyone,

I'm trying to better understand how to handle events inside Snort++ using
data_log inspector as example. But at the moment, I can't really read the
output file because it's always empty for me.

Until now, I did the following changes to snort.lua:

- Added a new line "data_log = { key = 'http_raw_uri' }
- Changed the "http_inspector = { }" to "http_server = { }"
(As recommended here: http://marc.info/?l=snort-users&m=147422221322032&w=2)

And ran the command:

"sudo snort -c /opt/snort/etc/snort/snort.lua -R
/opt/snort/etc/snort/samples.rules -r http.cap -A alert_ex --plugin-path
/opt/snort/lib/snort_extra"

The http.cap I'm using is the one located at https://wiki.wireshark.org/
SampleCaptures

What am I missing here?

Thanks in advance,
Ronin.

_______________________________________________
Snort-devel mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-devel

Please visit http://blog.snort.org for the latest news about Snort!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.