Re: Problem with Pulledpork3 timer
Jim Campbell <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
Noah, On page 12 of your guide, at the top is the pulledpork3.timer. Three lines need a minor change. Lines 3 and 4 say "RefuseManualStart=no" and "RefuseManualStop=no." In both cases the "no" should be "false." Later you have "OnCalendar=*-*-*13:35:00." There should be a space between the last "*" and the "13." Thanks for a really nice install guide. Jim Campbell On 2/21/2023 1:35 PM, Noah Dietrich wrote: > Hello, > > Can you let me know what the issue was (if it's something I need to > modify in the install guide)? > > thanks, > > Noah > > > > ---- On Tue, 21 Feb 2023 03:29:04 +0200 *Jim Campbell <[email protected]>* > wrote --- > > Never mind, I seem to have it working now. > > On 2/20/2023 1:16 PM, Jim Campbell wrote: > > > _______________________________________________ > Snort-users mailing list > [email protected] > Go to this URL to change user options or unsubscribe: > https://lists.snort.org/mailman/listinfo/snort-users > > To unsubscribe, send an email to: > [email protected] > > Please visit http://blog.snort.org to stay current on all the > latest Snort news! > > Please follow these rules: > https://snort.org/faq/what-is-the-mailing-list-etiquette > > I sent the following to Noah since I was using his writeup. He > hasn't answered so he must be busy. I would appreciate any help. > > ========================================================================================================== > > Noah, > > I'm running Snort3 using your writeup "Snort 3.1.18.0 on > Ubuntu 18 & 20" on Ubuntu 20.04.5. The Pulledpork3 timer is > failing with the following messages: > > > > This is the source file: > > > > I tried using RefuseManualStart=false but it didn't like that > either. > I tried using OnCalendar=*_*_* 09:38:00 but it didn't like > that either. There is a space between the * and 09. > > I am using Snort 3.1.18.0. The solution is probably simple but > I can't get my head around it. > > Thanks, > > Jim Campbell > The oldest script kiddie around > > _______________________________________________ > Snort-users mailing list > [email protected] <mailto:[email protected]> > Go to this URL to change user options or unsubscribe: > https://lists.snort.org/mailman/listinfo/snort-users <https://lists.snort.org/mailman/listinfo/snort-users> > > To unsubscribe, send an email to: > [email protected] <mailto:[email protected]> > > Please visithttp://blog.snort.org <http://blog.snort.org> to stay current on all the latest Snort news! > > Please follow these rules:https://snort.org/faq/what-is-the-mailing-list-etiquette <https://snort.org/faq/what-is-the-mailing-list-etiquette> > > > _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette