Re: same problem nobody help myself

"Vitalii Horbatov -X \(vhorbato - SOFTSERVE INC at Cisco\) via Snort-users" <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <MWHPR11MB1358833681D80CD20990C10BDBCB9@MWHPR11MB1358.namprd11.prod.outlook.com>
Ok, so you’re using pretty default config. Let’s try adding the  --daq pcap before --daq dump to your command line. So it will look like this:

sudo /usr/local/bin/snort -c /usr/local/etc/snort/snort.lua --daq-dir /usr/local/lib/daq --daq pcap --daq dump --daq-var lb_total=4 --daq-var fanout_type=hash -s 65535 -k all -l /var/log/snort -i enp0s25 --daq-var lb_id=1 -i wlp3s0 --daq-var lb_id=2 -z 2 -m 0x1b

Thanks,
Vitalii!


From: Dorian ROSSE <[email protected]>
Date: Monday, 9 May 2022, 14:02
To: Vitalii Horbatov -X (vhorbato - SOFTSERVE INC at Cisco) <[email protected]>
Cc: [email protected] <[email protected]>
Subject: RE: same problem nobody help myself
Hello Vitalii,


i launch the daq with snort with this line of command :

'''sudo /usr/local/bin/snort -c /usr/local/etc/snort/snort.lua --daq-dir /usr/local/lib/daq --daq dump --daq-var lb_total=4 --daq-var fanout_type=hash -s 65535 -k all -l /var/log/snort -i enp0s25 --daq-var lb_id=1 -i wlp3s0 --daq-var lb_id=2 -z 2 -m 0x1b'''

the file asked is in the attachment,

thanks you in advance for all the works brought,

regards.


Dorian ROSSE.
________________________________
De : Vitalii Horbatov -X (vhorbato - SOFTSERVE INC at Cisco) <[email protected]>
Envoyé : lundi 9 mai 2022 10:17
À : Dorian ROSSE <[email protected]>
Cc : [email protected] <[email protected]>
Objet : Re: same problem nobody help myself


Hello,

can you please upload your config file (snort.lua, as the error shows) or the line where you configure the daq-var?

I tried with your command line and it works for me.



Note that the configuration flags for the snort module in *.lua file are specified like this:

snort = {}

snort["--daq-var"] = "output=none"

or like this:
snort = {

    --daq-var = "output=none"

}



Thanks,
Vitalii!



From: Snort-users <[email protected]> on behalf of Dorian ROSSE via Snort-users <[email protected]>
Date: Sunday, 8 May 2022, 23:38
To: [email protected] <[email protected]>
Subject: [Snort-users] same problem nobody help myself

hello,





I fall on a daq error :



i don't understand the error i have tried to change one of the number after the --daq_var but it repeat the old problem where the both interface are missing :



does anybody can help myself because i don't success to go more far ! ?



'''sudo /usr/local/bin/snort -c /usr/local/etc/snort/snort.lua --daq-dir /usr/local/lib/daq --daq dump --daq-var lb_total=4 --daq-var fanout_type=hash -s 65535 -k all -l /var/log/snort -i enp0s25 --daq-var lb_id=1 -i wlp3s0 --daq-var lb_id=2 -z 2 -m 0x1b

--------------------------------------------------

o")~   Snort++ 3.1.21.0

--------------------------------------------------

Loading /usr/local/etc/snort/snort.lua:

Loading snort_defaults.lua:

Finished snort_defaults.lua:

Loading file_magic.lua:

Finished file_magic.lua:

Loading inline.lua:

Finished inline.lua:

Loading talos.lua:

Finished talos.lua:

host_tracker

hosts

packets

search_engine

so_proxy

stream

stream_ip

stream_tcp

stream_udp

stream_user

arp_spoof

dnp3

dns

imap

iec104

normalizer

pop

rpc_decode

sip

ssh

telnet

dce_http_server

gtp_inspect

port_scan

smtp

ftp_server

ftp_client

ftp_data

http_inspect

binder

alert_json

trace

ips

classifications

references

wizard

detection

reputation

    Processing blocklist file /usr/local/etc/snort/../lists/default.blocklist

    Reputation entries loaded: 1216, invalid: 0, re-defined: 0 (from file /usr/local/etc/snort/../lists/default.blocklist)

appid

file_policy

file_id

http2_inspect

dce_http_proxy

dce_udp

dce_tcp

dce_smb

ssl

netflow

modbus

back_orifice

stream_file

stream_icmp

profiler

alert_talos

snort

ERROR: /usr/local/etc/snort/snort.lua: snort.--daq-var is invalid

output

process

network

active

alerts

daq

decode

host_cache

Finished /usr/local/etc/snort/snort.lua:

--------------------------------------------------

rule counts

       total rules loaded: 600

            builtin rules: 600

            option chains: 600

            chain headers: 1

--------------------------------------------------

port rule counts

             tcp     udp    icmp      ip

     any     600       0       0       0

   total     600       0       0       0

--------------------------------------------------

ips policies rule stats

              id  loaded  shared enabled    file

               0     600       0     600    /usr/local/etc/snort/snort.lua

--------------------------------------------------

dump:pcap DAQ configured to inline.

FATAL: see prior 1 errors (0 warnings)

Fatal Error, Quitting..'''



thank you in advance for your help brought,



Regards.





Dorian ROSSE.

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.