Run snort in love IDS/IPS mode
abrar khan via Snort-users <[email protected]> Sun, 8 Oct 2023 22:48:11 -0500
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
Greetings, I have pulled down and started up ciscotalos/snort3 image and want to run the IDS/IPS mode to monitor live traffic. I am running the docker image on mac that is running ventura version 13.0 When i try to run this command: snort -c /home/snorty/snort3/etc/snort/snort.lua -q -Q --daq afpacket -i eno0 -A cmg in the docker container i see this error Couldn't construct a DAQ instance: create_instance: Could not open the PF_PACKET socket: Operation not permitted (-1) Is there a way i can run snort and monitor live traffic instead of capturing pcap files to run rules against? Thank you, Abrar Sent from my iPhone _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette