a more long line of command for launch where the two interface are again missing about those files
Dorian ROSSE via Snort-users <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general,gmane.comp.security.ids.snort.sigs |
|---|---|
| Message-ID | <DB7P193MB034644AF3EBC3566AAE03C19DAF99@DB7P193MB0346.EURP193.PROD.OUTLOOK.COM> |
hello,
a more long line of command for launch where the two interface are again missing about those files,
'''sudo /usr/local/bin/snort -c /usr/local/etc/snort/snort.lua --daq-dir /usr/local/lib/daq --daq dump --daq-var lb_total=4 --daq-var fanout_type=hash -s 65535 -k all -l /var/log/snort -i enp0s25 --daq-var lb_id=1 -i wlp3s0 --daq-var lb_id=2 -z 2 -m 0x1b
[sudo] Mot de passe de dorianrosse :
--------------------------------------------------
o")~ Snort++ 3.1.21.0
--------------------------------------------------
Loading /usr/local/etc/snort/snort.lua:
Loading snort_defaults.lua:
Finished snort_defaults.lua:
Loading file_magic.lua:
Finished file_magic.lua:
Loading inline.lua:
Finished inline.lua:
Loading talos.lua:
Finished talos.lua:
dce_smb
dce_tcp
dce_udp
dce_http_proxy
gtp_inspect
port_scan
smtp
ftp_client
ftp_data
http_inspect
http2_inspect
file_policy
appid
reputation
Processing blocklist file /usr/local/etc/snort/../lists/default.blocklist
Reputation entries loaded: 1216, invalid: 0, re-defined: 0 (from file /usr/local/etc/snort/../lists/default.blocklist)
output
detection
wizard
binder
references
classifications
alert_json
file_id
ftp_server
dce_http_server
telnet
ssl
ips
network
dnp3
arp_spoof
stream_udp
daq
host_cache
stream
trace
active
alerts
decode
host_tracker
hosts
packets
process
search_engine
so_proxy
snort
stream_ip
stream_icmp
stream_tcp
stream_user
stream_file
alert_talos
back_orifice
profiler
dns
imap
iec104
modbus
netflow
normalizer
pop
rpc_decode
sip
ssh
Finished /usr/local/etc/snort/snort.lua:
--------------------------------------------------
rule counts
total rules loaded: 600
builtin rules: 600
option chains: 600
chain headers: 1
--------------------------------------------------
port rule counts
tcp udp icmp ip
any 600 0 0 0
total 600 0 0 0
--------------------------------------------------
ips policies rule stats
id loaded shared enabled file
0 600 0 600 /usr/local/etc/snort/snort.lua
--------------------------------------------------
dump:pcap DAQ configured to inline.
Commencing packet processing
Couldn't construct a DAQ instance: pcap_daq_instantiate: Couldn't open file 'enp0s25' for reading: No such file or directory (-2)
Couldn't construct a DAQ instance: pcap_daq_instantiate: Couldn't open file 'wlp3s0' for reading: No such file or directory (-2)
--------------------------------------------------
Packet Statistics
--------------------------------------------------
Module Statistics
--------------------------------------------------
Summary Statistics
--------------------------------------------------
timing
runtime: 00:00:00
seconds: 0.001540
o")~ Snort exiting'''
thanks you in advance to help myself pass those errors,
Regards.
Dorian ROSSE.
_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users
To unsubscribe, send an email to:
[email protected]
Please visit http://blog.snort.org to stay current on all the latest Snort news!
Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette