Question on update to 3.1.36.0

David Melczer <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <BLAPR10MB5377A91C41A795AA5C0E09D8A1949@BLAPR10MB5377.namprd10.prod.outlook.com>
Good afternoon.

I just upgraded from 3.1.32.0 to 3.1.36.0 by recompiling source.  I've recompiled Snort, libdaq, and Snort_Extras as I have done every time in the past.  I use the latest pulledpork3 to grab ruleset updates, and I use the LightSPD ruleset.

For some reason, I keep getting this error, and the service now stops:

ERROR: /usr/local/snort/etc/snort/snort.lua: can't find file_id.file_rules

What is interesting is that if I comment out the file_magic section in snort.lua, everything works:

-- see file_magic.lua for file id rules
--file_id =
--{
--    file_rules = file_magic
--}

The second I re-enable this config section, I get the error again.  The file file_magic.lua DOES exist, and I do have the relevant include statement in section 1 of the snort.lua config file as follows:

include 'snort_defaults.lua'
include 'file_magic.lua'

To the best of my knowledge, the file_magic.lua file has not changed at all, unless it changed as part of the 3.1.36.0 upgrade.  There doesn't seem to be any problem including snort_defaults.lua, but for some reason it is as though file_magic.lua is not picked up.

Any ideas on what might have changed between 3.1.32.0 and 3.1.36.0 for this to no longer work?

Thank you in advance!

-Dave

David Z. Melczer  | Director of Information Technology

Greenbaum, Rowe, Smith & Davis LLP
Delivery: 99 Wood Avenue South | Iselin, NJ | 08830
Mailing: P.O. Box 5600 | Woodbridge, NJ | 07095
T: 732.476.3284  |  F: 732.476.3285  |  vCard<http://www.greenbaumlaw.com/vcard-1999.vcf>

[cid:[email protected]]
greenbaumlaw.com<http://www.greenbaumlaw.com/>
[cid:[email protected]]<https://www.linkedin.com/company/greenbaum-rowe-smith-&-davis-llp?trk=top_nav_home>
[cid:[email protected]]<https://twitter.com/greenbaumlaw>
[cid:[email protected]]<https://www.facebook.com/greenbaumlaw?fref=ts&ref=br_tf>

Disclaimer

The information contained in this communication from the sender is confidential. It is intended solely for use by the recipient and others authorized to receive it. If you are not the recipient, you are hereby notified that any disclosure, copying, distribution or taking action in relation of the contents of this information is strictly prohibited and may be unlawful.

This email has been scanned for viruses and malware, and may have been automatically archived by Mimecast Ltd, an innovator in Software as a Service (SaaS) for business. Providing a safer and more useful place for your human generated data. Specializing in; Security, archiving and compliance. To find out more visit the Mimecast website.

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
image001.jpg (image/jpeg, 3.4 KB) - not displayed
image002.png (image/png, 687 B) - not displayed
image003.png (image/png, 670 B) - not displayed
image004.png (image/png, 637 B) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.