Re: Snort.lua Question
Jim Campbell via Snort-users <[email protected]> Thu, 22 Jun 2023 13:04:43 -0400
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
That got rid of my error message. I was running from the command line and not as root. Thank you. On 6/22/2023 12:42 PM, Joel Esler wrote: > The bottom error looks like a permission problem. Like you’re not running as root or something. > > — > Sent from my iPhone > >> On Jun 22, 2023, at 12:32, Jim Campbell via Snort-users <[email protected]> wrote: >> >> Not getting an answer to my previous question I've tried a different approach. I installed newer dependencies and then Snort3 3.1.64.0. This is what /usr/local/bin/snort -V gives me: >> >> ,,_ -*> Snort++ <*- >> o" )~ Version 3.1.64.0 >> '''' By Martin Roesch & The Snort Team >> http://snort.org/contact#team >> Copyright (C) 2014-2023 Cisco and/or its affiliates. All rights reserved. >> Copyright (C) 1998-2013 Sourcefire, Inc., et al. >> Using DAQ version 3.0.12 >> Using LuaJIT version 2.1.0-beta3 >> Using OpenSSL 1.1.1f 31 Mar 2020 >> Using libpcap version 1.9.1 (with TPACKET_V3) >> Using PCRE version 8.45 2021-06-15 >> Using ZLIB version 1.2.11 >> Using Hyperscan version 5.4.2 2023-06-21 >> Using LZMA version 5.2.4 >> >> With this setup Snort almost runs. I toggle between two errors. If I invoke Snort3 with the following: >> >> ips = >> { >> -- use this to enable decoder and inspector alerts >> enable_builtin_rules = true, >> include = RULE_PATH .. "/pulledpork.rules", >> -- use include for rules files; be sure to set your path >> -- note that rules files can include other rules files >> -- (see also related path vars at the top of snort_defaults.lua) >> variables = default_variables >> } >> >> jim@jim-ThinkCentre-M82:~$ snort -c /usr/local/etc/snort/snort.lua -s 65535 -k none -l /var/log/snort/ -Q -D -u snort -g snort --daq afpacket -i "enp1s0:enp3s0" -m 0x1b --plugin-path /usr/local/etc/so_rules/ >> >> I get 267 errors: >> ... >> Finished file_id.rules_file: >> Loading ../rules/pulledpork.rules: >> ERROR: ../rules/pulledpork.rules:19 SO rule 34369 not loaded. >> ERROR: ../rules/pulledpork.rules:20 SO rule 35347 not loaded. >> ERROR: ../rules/pulledpork.rules:21 SO rule 35926 not loaded. >> ... >> >> The "--plugin-path /usr/local/etc/so_rules/" isn't getting the so_rules to load. >> >> =============================================== >> >> If I invoke snort3 with the following: >> >> ips = >> { >> -- use this to enable decoder and inspector alerts >> enable_builtin_rules = true, >> include = RULE_PATH .. "/pulledpork.rules", >> include = PLUGIN_RULE_PATH, >> -- use include for rules files; be sure to set your path >> -- note that rules files can include other rules files >> -- (see also related path vars at the top of snort_defaults.lua) >> variables = default_variables >> } >> >> jim@jim-ThinkCentre-M82:~$ snort -c /usr/local/etc/snort/snort.lua -s 65535 -k none -l /var/log/snort/ -Q -D -u snort -g snort --daq afpacket -i "enp1s0:enp3s0" -m 0x1b >> >> The so_rules load but I get the following error: >> >> -------------------------------------------------- >> afpacket DAQ configured to inline. >> initializing daemon mode >> child process is 137323 >> Commencing packet processing >> Couldn't construct a DAQ instance: create_instance: Could not open the PF_PACKET socket: Operation not permitted (-1) >> -------------------------------------------------- >> >> Any help would be much appreciated. >> >> Jim Campbell >> >> >> >> >> >> >> _______________________________________________ >> Snort-users mailing list >> [email protected] >> Go to this URL to change user options or unsubscribe: >> https://lists.snort.org/mailman/listinfo/snort-users >> >> To unsubscribe, send an email to: >> [email protected] >> >> Please visit http://blog.snort.org to stay current on all the latest Snort news! >> >> Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette