Run snort in love IDS/IPS mode

abrar khan via Snort-users <[email protected]> Sun, 8 Oct 2023 22:48:11 -0500
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <[email protected]>
Greetings,
I have pulled down and started up ciscotalos/snort3 image and want to run the IDS/IPS mode to monitor live traffic. I am running the docker image on mac that is running ventura version 13.0

When i try to run this command: snort -c /home/snorty/snort3/etc/snort/snort.lua -q -Q --daq afpacket -i eno0 -A cmg in the docker container i see this error
Couldn't construct a DAQ instance: create_instance: Could not open the PF_PACKET socket: Operation not permitted (-1)

Is there a way i can run snort and monitor live traffic instead of capturing pcap files to run rules against?

Thank you,
Abrar

Sent from my iPhone

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette