Re: same problem nobody help myself

"Vitalii Horbatov -X \(vhorbato - SOFTSERVE INC at Cisco\) via Snort-users" <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <MWHPR11MB1358ED4CF212489B08CEFDDFDBCA9@MWHPR11MB1358.namprd11.prod.outlook.com>
Hi,

as far I see from your configuration, you have only the built-in rules enabled. You can download Snort3 Community Rules from https://snort.org/downloads or use the PulledPork3 for example. After you get the rules, you need to specify the path to them using the ips.include parameter. For example:

ips =
{
    variables = default_variables,
    include = "/fake/path/snort3-community-rules/snort3-community.rules"
}

After that, you`ll get a lot more rules.

Thanks,
Vitalii!

From: Dorian ROSSE <[email protected]>
Date: Friday, 13 May 2022, 16:56
To: Vitalii Horbatov -X (vhorbato - SOFTSERVE INC at Cisco) <[email protected]>
Cc: [email protected] <[email protected]>
Subject: RE: same problem nobody help myself
hello Vitalii,


your line of command works well thank you,

do you understand why i am run only 600 rules ?

'''--------------------------------------------------
o")~   Snort++ 3.1.21.0
--------------------------------------------------
Loading /usr/local/etc/snort/snort.lua:
Loading snort_defaults.lua:
Finished snort_defaults.lua:
Loading file_magic.lua:
Finished file_magic.lua:
Loading inline.lua:
Finished inline.lua:
Loading talos.lua:
Finished talos.lua:
output
alert_json
ips
classifications
references
back_orifice
wizard
imap
pop
rpc_decode
sip
ssl
stream
dce_smb
ftp_client
ftp_server
snort
dce_http_server
dce_udp
ftp_data
http_inspect
http2_inspect
file_id
ssh
file_policy
appid
reputation
    Processing blocklist file /usr/local/etc/snort/../lists/default.blocklist
    Reputation entries loaded: 1216, invalid: 0, re-defined: 0 (from file /usr/local/etc/snort/../lists/default.blocklist)
normalizer
netflow
modbus
iec104
detection
dns
dnp3
binder
arp_spoof
stream_file
stream_user
stream_udp
stream_tcp
stream_icmp
stream_ip
active
alerts
decode
host_cache
host_tracker
hosts
network
telnet
dce_tcp
dce_http_proxy
gtp_inspect
port_scan
smtp
daq
packets
process
search_engine
so_proxy
trace
alert_talos
profiler
Finished /usr/local/etc/snort/snort.lua:
--------------------------------------------------
rule counts
       total rules loaded: 600
            builtin rules: 600
            option chains: 600
            chain headers: 1
--------------------------------------------------
port rule counts
             tcp     udp    icmp      ip
     any     600       0       0       0
   total     600       0       0       0
--------------------------------------------------
ips policies rule stats
              id  loaded  shared enabled    file
               0     600       0     600    /usr/local/etc/snort/snort.lua
--------------------------------------------------
dump:pcap DAQ configured to inline.
Commencing packet processing
++ [0] enp0s25
++ [1] wlp3s0
'''
thank you in advance for your soon answers,

Regards.


Dorian ROSSE.
________________________________
De : Vitalii Horbatov -X (vhorbato - SOFTSERVE INC at Cisco) <[email protected]>
Envoyé : jeudi 12 mai 2022 10:21
À : Dorian ROSSE <[email protected]>
Cc : [email protected] <[email protected]>
Objet : Re: same problem nobody help myself


Ok, so you’re using pretty default config. Let’s try adding the  --daq pcap before --daq dump to your command line. So it will look like this:

sudo /usr/local/bin/snort -c /usr/local/etc/snort/snort.lua --daq-dir /usr/local/lib/daq --daq pcap --daq dump --daq-var lb_total=4 --daq-var fanout_type=hash -s 65535 -k all -l /var/log/snort -i enp0s25 --daq-var lb_id=1 -i wlp3s0 --daq-var lb_id=2 -z 2 -m 0x1b



Thanks,
Vitalii!



From: Dorian ROSSE <[email protected]>
Date: Monday, 9 May 2022, 14:02
To: Vitalii Horbatov -X (vhorbato - SOFTSERVE INC at Cisco) <[email protected]>
Cc: [email protected] <[email protected]>
Subject: RE: same problem nobody help myself

Hello Vitalii,





i launch the daq with snort with this line of command :



'''sudo /usr/local/bin/snort -c /usr/local/etc/snort/snort.lua --daq-dir /usr/local/lib/daq --daq dump --daq-var lb_total=4 --daq-var fanout_type=hash -s 65535 -k all -l /var/log/snort -i enp0s25 --daq-var lb_id=1 -i wlp3s0 --daq-var lb_id=2 -z 2 -m 0x1b'''



the file asked is in the attachment,



thanks you in advance for all the works brought,



regards.





Dorian ROSSE.

________________________________

De : Vitalii Horbatov -X (vhorbato - SOFTSERVE INC at Cisco) <[email protected]>
Envoyé : lundi 9 mai 2022 10:17
À : Dorian ROSSE <[email protected]>
Cc : [email protected] <[email protected]>
Objet : Re: same problem nobody help myself



Hello,

can you please upload your config file (snort.lua, as the error shows) or the line where you configure the daq-var?

I tried with your command line and it works for me.



Note that the configuration flags for the snort module in *.lua file are specified like this:

snort = {}

snort["--daq-var"] = "output=none"

or like this:
snort = {

    --daq-var = "output=none"

}



Thanks,
Vitalii!



From: Snort-users <[email protected]> on behalf of Dorian ROSSE via Snort-users <[email protected]>
Date: Sunday, 8 May 2022, 23:38
To: [email protected] <[email protected]>
Subject: [Snort-users] same problem nobody help myself

hello,





I fall on a daq error :



i don't understand the error i have tried to change one of the number after the --daq_var but it repeat the old problem where the both interface are missing :



does anybody can help myself because i don't success to go more far ! ?



'''sudo /usr/local/bin/snort -c /usr/local/etc/snort/snort.lua --daq-dir /usr/local/lib/daq --daq dump --daq-var lb_total=4 --daq-var fanout_type=hash -s 65535 -k all -l /var/log/snort -i enp0s25 --daq-var lb_id=1 -i wlp3s0 --daq-var lb_id=2 -z 2 -m 0x1b

--------------------------------------------------

o")~   Snort++ 3.1.21.0

--------------------------------------------------

Loading /usr/local/etc/snort/snort.lua:

Loading snort_defaults.lua:

Finished snort_defaults.lua:

Loading file_magic.lua:

Finished file_magic.lua:

Loading inline.lua:

Finished inline.lua:

Loading talos.lua:

Finished talos.lua:

host_tracker

hosts

packets

search_engine

so_proxy

stream

stream_ip

stream_tcp

stream_udp

stream_user

arp_spoof

dnp3

dns

imap

iec104

normalizer

pop

rpc_decode

sip

ssh

telnet

dce_http_server

gtp_inspect

port_scan

smtp

ftp_server

ftp_client

ftp_data

http_inspect

binder

alert_json

trace

ips

classifications

references

wizard

detection

reputation

    Processing blocklist file /usr/local/etc/snort/../lists/default.blocklist

    Reputation entries loaded: 1216, invalid: 0, re-defined: 0 (from file /usr/local/etc/snort/../lists/default.blocklist)

appid

file_policy

file_id

http2_inspect

dce_http_proxy

dce_udp

dce_tcp

dce_smb

ssl

netflow

modbus

back_orifice

stream_file

stream_icmp

profiler

alert_talos

snort

ERROR: /usr/local/etc/snort/snort.lua: snort.--daq-var is invalid

output

process

network

active

alerts

daq

decode

host_cache

Finished /usr/local/etc/snort/snort.lua:

--------------------------------------------------

rule counts

       total rules loaded: 600

            builtin rules: 600

            option chains: 600

            chain headers: 1

--------------------------------------------------

port rule counts

             tcp     udp    icmp      ip

     any     600       0       0       0

   total     600       0       0       0

--------------------------------------------------

ips policies rule stats

              id  loaded  shared enabled    file

               0     600       0     600    /usr/local/etc/snort/snort.lua

--------------------------------------------------

dump:pcap DAQ configured to inline.

FATAL: see prior 1 errors (0 warnings)

Fatal Error, Quitting..'''



thank you in advance for your help brought,



Regards.





Dorian ROSSE.

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.