Re: SnortML
Joel Esler via Snort-users <[email protected]> Mon, 1 Apr 2024 17:17:55 -0400
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
Should just be a matter of what mode you’re running it in. Not running it with a -r argument. > On Apr 1, 2024, at 13:03, Ron Jenkins via Snort-users <[email protected]> wrote: > > Looking for any documentation with ML running live in IDS daemon mode, not running against PCAPs. > > > Thx > > From: Nick Godwod <[email protected] <mailto:[email protected]>> > Sent: Monday, April 1, 2024 11:58 AM > To: Ron Jenkins <[email protected] <mailto:[email protected]>> > Cc: Patrick Mullen (pamullen) <[email protected] <mailto:[email protected]>>; Yurii Chalov -X (ychalov - SOFTSERVE INC at Cisco) <[email protected] <mailto:[email protected]>>; [email protected] <mailto:[email protected]> > Subject: Re: [Snort-users] SnortML > > CAUTION: This email originated from outside your organization. Exercise caution when opening attachments or clicking links, especially from unknown senders. > > You should be able to find modules on github like this. > Lots of folks run a preconfigured version. > Sent from my iPhone > > > On Apr 1, 2024, at 10:45, Ron Jenkins via Snort-users <[email protected] <mailto:[email protected]>> wrote: > > > Good morning > > Are there any already configured models that I can download for use with Snort in IDS daemon mode? > > > Thank you! > > From: Patrick Mullen (pamullen) <[email protected] <mailto:[email protected]>> > Sent: Thursday, March 21, 2024 6:51 AM > To: Ron Jenkins <[email protected] <mailto:[email protected]>>; Yurii Chalov -X (ychalov - SOFTSERVE INC at Cisco) <[email protected] <mailto:[email protected]>> > Cc: Nihal Desai (nihdesai) <[email protected] <mailto:[email protected]>>; [email protected] <mailto:[email protected]> > Subject: RE: [Snort-users] SnortML > > CAUTION: This email originated from outside your organization. Exercise caution when opening attachments or clicking links, especially from unknown senders. > > Ron, > > You will need to create your own model file for doing the detection itself. > > There is a blog post about the new feature and how to create a model using tools in the repository. > > https://blog.snort.org/2024/03/talos-launching-new-machine-learning.html > > It’s great to see someone using the tech! Let me know if you’re able to create your own model and how it goes. > > > Thanks, > > ~Patrick > > From: Ron Jenkins <[email protected] <mailto:[email protected]>> > Sent: Wednesday, March 20, 2024 8:38 AM > To: Yurii Chalov -X (ychalov - SOFTSERVE INC at Cisco) <[email protected] <mailto:[email protected]>> > Cc: Nihal Desai (nihdesai) <[email protected] <mailto:[email protected]>>; [email protected] <mailto:[email protected]> > Subject: Re: [Snort-users] SnortML > > Good morning > > Success! See below. I re-ran the config for Snort v3.1.82 and now it shows LibML: ON; see below. > > Are there any detail documentation in using the new SnortML? Is there a default setup for it? > > > Thank you!!! > > <image001.png> > > <image002.png> > > > <image003.png> > > > > From: Yurii Chalov -X (ychalov - SOFTSERVE INC at Cisco) <[email protected] <mailto:[email protected]>> > Sent: Wednesday, March 20, 2024 3:33 AM > To: Ron Jenkins <[email protected] <mailto:[email protected]>> > Cc: Nihal Desai (nihdesai) <[email protected] <mailto:[email protected]>>; [email protected] <mailto:[email protected]> > Subject: Re: SnortML > > CAUTION: This email originated from outside your organization. Exercise caution when opening attachments or clicking links, especially from unknown senders. > > Hi Ron! > > Now try to add a line "#include <cstdint>” into the file libml-1.0.0/vendor/tensorflow/tensorflow/lite/kernels/internal/spectrogram.cc <http://spectrogram.cc/> on the line 20 and make previous steps I’ve mentioned in the previous email. > > Best Wishes > > Yurii Chalov > > > On 19 Mar 2024, at 17:43, Ron Jenkins <[email protected] <mailto:[email protected]>> wrote: > > Still no luck, see below. > > > Thanks > > [ 0%] Built target clog > [ 0%] Built target normalization > [ 0%] Built target absl_log_severity > [ 0%] Built target pthreadpool > [ 0%] Built target absl_spinlock_wait > [ 0%] Built target absl_strerror > [ 0%] Built target absl_int128 > [ 4%] Built target absl_time_zone > [ 4%] Built target absl_exponential_biased > [ 4%] Built target absl_flags_commandlineflag_internal > [ 4%] Built target absl_civil_time > [ 4%] Built target farmhash > [ 4%] Built target fft2d_fftsg > [ 4%] Built target ruy_wait > [ 4%] Built target flatbuffers > [ 4%] Built target ruy_system_aligned_alloc > [ 4%] Built target ruy_profiler_instrumentation > [ 4%] Built target ruy_denormal > [ 4%] Built target ruy_apply_multiplier > [ 4%] Built target ruy_have_built_path_for_avx512 > [ 4%] Built target ruy_have_built_path_for_avx2_fma > [ 4%] Built target ruy_have_built_path_for_avx > [ 4%] Built target allocator > [ 4%] Built target microparams_init > [ 4%] Built target cpuinfo > [ 4%] Built target logging > [ 4%] Built target cache > [ 4%] Built target mutex > [ 4%] Built target absl_raw_logging_internal > [ 4%] Built target operators > [ 8%] Built target subgraph > [ 8%] Built target fft2d_fftsg2d > [ 8%] Built target ruy_cpuinfo > [ 13%] Built target ruy_prepacked_cache > [ 17%] Built target ruy_allocator > [ 17%] Built target ruy_block_map > [ 17%] Built target ruy_blocking_counter > [ 17%] Built target post-operation > [ 17%] Built target absl_base > [ 17%] Built target absl_throw_delegate > [ 17%] Built target absl_debugging_internal > [ 17%] Built target absl_bad_optional_access > [ 21%] Built target absl_bad_variant_access > [ 21%] Built target absl_city > [ 21%] Built target absl_low_level_hash > [ 21%] Built target absl_cordz_functions > [ 21%] Built target ruy_tune > [ 21%] Built target ruy_thread_pool > [ 21%] Built target absl_malloc_internal > [ 21%] Built target absl_stacktrace > [ 21%] Built target absl_demangle_internal > [ 21%] Built target absl_strings_internal > [ 21%] Built target absl_graphcycles_internal > [ 21%] Built target ruy_pack_arm > [ 21%] Built target ruy_kernel_arm > [ 21%] Built target ruy_kernel_avx512 > [ 21%] Built target ruy_pack_avx512 > [ 21%] Built target ruy_kernel_avx2_fma > [ 21%] Built target ruy_pack_avx2_fma > [ 21%] Built target ruy_kernel_avx > [ 21%] Built target ruy_pack_avx > [ 21%] Built target ruy_ctx > [ 21%] Built target ruy_context > [ 21%] Built target ruy_trmul > [ 21%] Built target absl_strings > [ 21%] Built target ruy_context_get_ctx > [ 21%] Built target ruy_prepare_packed_matrices > [ 21%] Built target absl_symbolize > [ 21%] Built target absl_flags_commandlineflag > [ 21%] Built target absl_time > [ 26%] Built target absl_str_format_internal > [ 26%] Built target absl_hash > [ 26%] Built target ruy_frontend > [ 26%] Built target absl_cord_internal > [ 26%] Built target absl_flags_marshalling > [ 26%] Built target absl_synchronization > [ 26%] Built target absl_flags_private_handle_accessor > [ 26%] Built target absl_flags_program_name > [ 26%] Built target absl_hashtablez_sampler > [ 26%] Built target absl_cordz_handle > [ 26%] Built target absl_flags_config > [ 26%] Built target absl_raw_hash_set > [ 26%] Built target absl_cordz_info > [ 26%] Built target absl_flags_internal > [ 26%] Built target absl_cord > [ 69%] Built target XNNPACK > [ 69%] Built target absl_flags_reflection > [ 69%] Built target absl_status > [ 73%] Built target absl_flags > [ 73%] Building CXX object vendor/tensorflow/tensorflow/lite/CMakeFiles/tensorflow-lite.dir/kernels/add.cc.o > [ 73%] Building CXX object vendor/tensorflow/tensorflow/lite/CMakeFiles/tensorflow-lite.dir/kernels/internal/spectrogram.cc.o > [ 73%] Building CXX object vendor/tensorflow/tensorflow/lite/CMakeFiles/tensorflow-lite.dir/kernels/add_n.cc.o > [ 73%] Building CXX object vendor/tensorflow/tensorflow/lite/CMakeFiles/tensorflow-lite.dir/kernels/arg_min_max.cc.o > /downloads/snort3/libml-1.0.0/vendor/tensorflow/tensorflow/lite/kernels/internal/spectrogram.cc:46:22: error: ‘uint32_t’ was not declared in this scope > 46 | inline int Log2Floor(uint32_t n) { > | ^~~~~~~~ > /downloads/snort3/libml-1.0.0/vendor/tensorflow/tensorflow/lite/kernels/internal/spectrogram.cc:20:1: note: ‘uint32_t’ is defined in header ‘<cstdint>’; did you forget to ‘#include <cstdint>’? > 19 | #include <math.h> > +++ |+#include <cstdint> > 20 | > /downloads/snort3/libml-1.0.0/vendor/tensorflow/tensorflow/lite/kernels/internal/spectrogram.cc:61:24: error: ‘uint32_t’ was not declared in this scope > 61 | inline int Log2Ceiling(uint32_t n) { > | ^~~~~~~~ > /downloads/snort3/libml-1.0.0/vendor/tensorflow/tensorflow/lite/kernels/internal/spectrogram.cc:61:24: note: ‘uint32_t’ is defined in header ‘<cstdint>’; did you forget to ‘#include <cstdint>’? > /downloads/snort3/libml-1.0.0/vendor/tensorflow/tensorflow/lite/kernels/internal/spectrogram.cc:69:8: error: ‘uint32_t’ does not name a type > 69 | inline uint32_t NextPowerOfTwo(uint32_t value) { > | ^~~~~~~~ > /downloads/snort3/libml-1.0.0/vendor/tensorflow/tensorflow/lite/kernels/internal/spectrogram.cc:69:8: note: ‘uint32_t’ is defined in header ‘<cstdint>’; did you forget to ‘#include <cstdint>’? > /downloads/snort3/libml-1.0.0/vendor/tensorflow/tensorflow/lite/kernels/internal/spectrogram.cc: In member function ‘bool tflite::internal::Spectrogram::Initialize(const std::vector<double>&, int)’: > /downloads/snort3/libml-1.0.0/vendor/tensorflow/tensorflow/lite/kernels/internal/spectrogram.cc:92:17: error: ‘NextPowerOfTwo’ was not declared in this scope > 92 | fft_length_ = NextPowerOfTwo(window_length_); > | ^~~~~~~~~~~~~~ > At global scope: > cc1plus: note: unrecognized command-line option ‘-Wno-unknown-attributes’ may have been intended to silence earlier diagnostics > make[2]: *** [vendor/tensorflow/tensorflow/lite/CMakeFiles/tensorflow-lite.dir/build.make:566: vendor/tensorflow/tensorflow/lite/CMakeFiles/tensorflow-lite.dir/kernels/internal/spectrogram.cc.o] Error 1 > make[2]: *** Waiting for unfinished jobs.... > make[1]: *** [CMakeFiles/Makefile2:6169: vendor/tensorflow/tensorflow/lite/CMakeFiles/tensorflow-lite.dir/all] Error 2 > make: *** [Makefile:136: all] Error 2 > > > -----Original Message----- > From: Yurii Chalov -X (ychalov - SOFTSERVE INC at Cisco) <[email protected] <mailto:[email protected]>> > Sent: Tuesday, March 19, 2024 11:18 AM > To: Ron Jenkins <[email protected] <mailto:[email protected]>> > Cc: Nihal Desai (nihdesai) <[email protected] <mailto:[email protected]>>; [email protected] <mailto:[email protected]> > Subject: Re: SnortML > > CAUTION: This email originated from outside your organization. Exercise caution when opening attachments or clicking links, especially from unknown senders. > > Hey Ron! > > So as I see, the fix of this problem is in progress. Anyway, you can try to fix using these steps > > 1. run './configure.sh' > 2. run ‘cd build’ > 3. in the file ‘CMakeCache.txt’ find 'CMAKE_C_FLAGS:STRING’ and 'CMAKE_CXX_FLAGS:STRING’. Add to these fields '-Wno-error=stringop-overflow=‘ > > The example is below: > CMAKE_C_FLAGS:STRING=-Wno-error=stringop-overflow= > CMAKE_CXX_FLAGS:STRING=-Wno-error=stringop-overflow= > > 4. run 'sudo make -j$(nproc) install’ > > Best wishes > > Yurii Chalov > > > > On 19 Mar 2024, at 16:41, Ron Jenkins <[email protected] <mailto:[email protected]>> wrote: > > Please see below. > Thanks > [ 0%] Built target normalization > [ 0%] Built target clog > [ 0%] Built target pthreadpool > [ 0%] Built target absl_log_severity > [ 0%] Built target absl_spinlock_wait [ 0%] Built target > absl_strerror [ 0%] Built target absl_int128 [ 4%] Built target > absl_time_zone [ 4%] Built target absl_exponential_biased [ 4%] > Built target absl_flags_commandlineflag_internal > [ 4%] Built target absl_civil_time > [ 4%] Built target farmhash > [ 4%] Built target fft2d_fftsg > [ 4%] Built target ruy_system_aligned_alloc [ 4%] Built target > ruy_wait [ 4%] Building CXX object > vendor/flatbuffers/CMakeFiles/flatbuffers.dir/src/reflection.cpp.o > [ 4%] Built target ruy_profiler_instrumentation [ 4%] Built target > ruy_apply_multiplier [ 4%] Built target ruy_denormal [ 4%] Built > target ruy_have_built_path_for_avx512 [ 4%] Built target > ruy_have_built_path_for_avx2_fma [ 4%] Built target > ruy_have_built_path_for_avx [ 4%] Built target allocator [ 4%] Built > target cpuinfo [ 4%] Built target microparams_init [ 4%] Built > target logging [ 4%] Built target cache [ 8%] Built target subgraph > [ 8%] Built target operators [ 8%] Built target mutex [ 8%] Built > target absl_raw_logging_internal [ 8%] Built target fft2d_fftsg2d [ > 8%] Built target ruy_cpuinfo [ 13%] Built target ruy_prepacked_cache [ > 17%] Built target ruy_allocator [ 17%] Built target ruy_block_map [ > 17%] Built target ruy_blocking_counter [ 17%] Built target > post-operation [ 17%] Built target absl_base [ 17%] Built target > absl_throw_delegate [ 17%] Built target absl_debugging_internal [ 17%] > Built target absl_bad_optional_access [ 21%] Built target > absl_bad_variant_access [ 21%] Built target absl_city [ 21%] Built > target absl_low_level_hash [ 21%] Built target absl_cordz_functions [ > 21%] Built target ruy_tune [ 21%] Built target ruy_thread_pool [ 21%] > Built target absl_malloc_internal [ 21%] Built target absl_stacktrace > [ 21%] Built target absl_strings_internal [ 21%] Built target > absl_demangle_internal [ 21%] Built target ruy_kernel_arm [ 21%] Built > target absl_graphcycles_internal [ 21%] Built target ruy_pack_arm [ > 21%] Built target ruy_kernel_avx512 [ 21%] Built target > ruy_pack_avx512 [ 21%] Built target ruy_kernel_avx2_fma [ 21%] Built > target ruy_kernel_avx [ 21%] Built target ruy_pack_avx2_fma [ 21%] > Building CXX object vendor/ruy/ruy/CMakeFiles/ruy_ctx.dir/ctx.cc.o > [ 65%] Built target XNNPACK > [ 65%] Built target ruy_pack_avx > [ 65%] Built target absl_strings > [ 65%] Built target absl_symbolize > [ 65%] Built target absl_time > [ 65%] Built target absl_flags_commandlineflag [ 69%] Built target > absl_str_format_internal [ 69%] Built target absl_hash [ 69%] Built > target absl_cord_internal [ 69%] Built target absl_synchronization [ > 69%] Built target absl_flags_marshalling [ 69%] Built target > absl_flags_private_handle_accessor > [ 69%] Built target absl_cordz_handle > [ 69%] Built target absl_hashtablez_sampler [ 69%] Built target > absl_flags_program_name [ 69%] Built target absl_cordz_info [ 69%] > Built target absl_raw_hash_set [ 69%] Built target absl_flags_config [ > 69%] Built target absl_cord [ 69%] Built target absl_flags_internal [ > 69%] Built target absl_flags_reflection [ 69%] Built target > absl_status [ 73%] Built target absl_flags [ 73%] Linking CXX static > library libruy_ctx.a [ 73%] Built target ruy_ctx [ 73%] Building CXX > object vendor/ruy/ruy/CMakeFiles/ruy_context.dir/context.cc.o > [ 73%] Building CXX object > vendor/ruy/ruy/CMakeFiles/ruy_trmul.dir/trmul.cc.o > [ 73%] Building CXX object > vendor/ruy/ruy/CMakeFiles/ruy_prepare_packed_matrices.dir/prepare_pack > ed_matrices.cc.o [ 73%] Linking CXX static library > libruy_prepare_packed_matrices.a [ 73%] Built target > ruy_prepare_packed_matrices [ 73%] Linking CXX static library > libruy_trmul.a [ 73%] Linking CXX static library libruy_context.a [ > 73%] Built target ruy_trmul [ 73%] Built target ruy_context [ 73%] > Building CXX object > vendor/ruy/ruy/CMakeFiles/ruy_frontend.dir/frontend.cc.o > [ 73%] Building CXX object > vendor/ruy/ruy/CMakeFiles/ruy_context_get_ctx.dir/context_get_ctx.cc.o > In file included from /usr/include/c++/13/string:51, > from /downloads/snort3/libml-1.0.0/vendor/flatbuffers/include/flatbuffers/base.h:41, > from /downloads/snort3/libml-1.0.0/vendor/flatbuffers/include/flatbuffers/array.h:20, > from /downloads/snort3/libml-1.0.0/vendor/flatbuffers/include/flatbuffers/flatbuffers.h:22, > from /downloads/snort3/libml-1.0.0/vendor/flatbuffers/include/flatbuffers/reflection_generated.h:7, > from /downloads/snort3/libml-1.0.0/vendor/flatbuffers/include/flatbuffers/reflection.h:25, > from /downloads/snort3/libml-1.0.0/vendor/flatbuffers/src/reflection.cpp:17: > In static member function ‘static _Up* std::__copy_move<_IsMove, true, std::random_access_iterator_tag>::__copy_m(_Tp*, _Tp*, _Up*) [with _Tp = const unsigned char; _Up = unsigned char; bool _IsMove = false]’, > inlined from ‘_OI std::__copy_move_a2(_II, _II, _OI) [with bool _IsMove = false; _II = const unsigned char*; _OI = unsigned char*]’ at /usr/include/c++/13/bits/stl_algobase.h:506:30, > inlined from ‘_OI std::__copy_move_a1(_II, _II, _OI) [with bool _IsMove = false; _II = const unsigned char*; _OI = unsigned char*]’ at /usr/include/c++/13/bits/stl_algobase.h:533:42, > inlined from ‘_OI std::__copy_move_a(_II, _II, _OI) [with bool _IsMove = false; _II = const unsigned char*; _OI = unsigned char*]’ at /usr/include/c++/13/bits/stl_algobase.h:540:31, > inlined from ‘_OI std::copy(_II, _II, _OI) [with _II = const unsigned char*; _OI = unsigned char*]’ at /usr/include/c++/13/bits/stl_algobase.h:633:7, > inlined from ‘static _ForwardIterator std::__uninitialized_copy<true>::__uninit_copy(_InputIterator, _InputIterator, _ForwardIterator) [with _InputIterator = const unsigned char*; _ForwardIterator = unsigned char*]’ at /usr/include/c++/13/bits/stl_uninitialized.h:147:27, > inlined from ‘_ForwardIterator std::uninitialized_copy(_InputIterator, _InputIterator, _ForwardIterator) [with _InputIterator = const unsigned char*; _ForwardIterator = unsigned char*]’ at /usr/include/c++/13/bits/stl_uninitialized.h:185:15, > inlined from ‘_ForwardIterator std::__uninitialized_copy_a(_InputIterator, _InputIterator, _ForwardIterator, allocator<_Tp>&) [with _InputIterator = const unsigned char*; _ForwardIterator = unsigned char*; _Tp = unsigned char]’ at /usr/include/c++/13/bits/stl_uninitialized.h:373:37, > inlined from ‘void std::vector<_Tp, _Alloc>::_M_range_insert(iterator, _ForwardIterator, _ForwardIterator, std::forward_iterator_tag) [with _ForwardIterator = const unsigned char*; _Tp = unsigned char; _Alloc = std::allocator<unsigned char>]’ at /usr/include/c++/13/bits/vector.tcc:814:38, > inlined from ‘std::vector<_Tp, _Alloc>::iterator std::vector<_Tp, _Alloc>::insert(const_iterator, _InputIterator, _InputIterator) [with _InputIterator = const unsigned char*; <template-parameter-2-2> = void; _Tp = unsigned char; _Alloc = std::allocator<unsigned char>]’ at /usr/include/c++/13/bits/stl_vector.h:1483:19, > inlined from ‘const uint8_t* flatbuffers::AddFlatBuffer(std::vector<unsigned char>&, const uint8_t*, size_t)’ at /downloads/snort3/libml-1.0.0/vendor/flatbuffers/src/reflection.cpp:365:17: > /usr/include/c++/13/bits/stl_algobase.h:437:30: error: ‘void* __builtin_memcpy(void*, const void*, long unsigned int)’ writing between 2 and 9223372036854775803 bytes into a region of size 0 overflows the destination [-Werror=stringop-overflow=] > 437 | __builtin_memmove(__result, __first, sizeof(_Tp) * _Num); > | ~~~~~~~~~~~~~~~~~^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ > In file included from /usr/include/x86_64-linux-gnu/c++/13/bits/c++allocator.h:33, > from /usr/include/c++/13/bits/allocator.h:46, > from /usr/include/c++/13/string:43: > In member function ‘_Tp* std::__new_allocator<_Tp>::allocate(size_type, const void*) [with _Tp = unsigned char]’, > inlined from ‘static _Tp* std::allocator_traits<std::allocator<_CharT> >::allocate(allocator_type&, size_type) [with _Tp = unsigned char]’ at /usr/include/c++/13/bits/alloc_traits.h:482:28, > inlined from ‘std::_Vector_base<_Tp, _Alloc>::pointer std::_Vector_base<_Tp, _Alloc>::_M_allocate(std::size_t) [with _Tp = unsigned char; _Alloc = std::allocator<unsigned char>]’ at /usr/include/c++/13/bits/stl_vector.h:378:33, > inlined from ‘void std::vector<_Tp, _Alloc>::_M_range_insert(iterator, _ForwardIterator, _ForwardIterator, std::forward_iterator_tag) [with _ForwardIterator = const unsigned char*; _Tp = unsigned char; _Alloc = std::allocator<unsigned char>]’ at /usr/include/c++/13/bits/vector.tcc:805:40, > inlined from ‘std::vector<_Tp, _Alloc>::iterator std::vector<_Tp, _Alloc>::insert(const_iterator, _InputIterator, _InputIterator) [with _InputIterator = const unsigned char*; <template-parameter-2-2> = void; _Tp = unsigned char; _Alloc = std::allocator<unsigned char>]’ at /usr/include/c++/13/bits/stl_vector.h:1483:19, > inlined from ‘const uint8_t* flatbuffers::AddFlatBuffer(std::vector<unsigned char>&, const uint8_t*, size_t)’ at /downloads/snort3/libml-1.0.0/vendor/flatbuffers/src/reflection.cpp:365:17: > /usr/include/c++/13/bits/new_allocator.h:151:55: note: at offset [-9223372036854775808, -4] into destination object of size [4, 9223372036854775807] allocated by ‘operator new’ > 151 | return static_cast<_Tp*>(_GLIBCXX_OPERATOR_NEW(__n * sizeof(_Tp))); > | ^ > [ 73%] Linking CXX static library libruy_frontend.a [ 73%] Built > target ruy_frontend [ 73%] Linking CXX static library > libruy_context_get_ctx.a [ 73%] Built target ruy_context_get_ctx At > global scope: > cc1plus: note: unrecognized command-line option > ‘-Wno-unknown-attributes’ may have been intended to silence earlier > diagnostics > cc1plus: all warnings being treated as errors > make[2]: *** > [vendor/flatbuffers/CMakeFiles/flatbuffers.dir/build.make:104: > vendor/flatbuffers/CMakeFiles/flatbuffers.dir/src/reflection.cpp.o] > Error 1 > make[1]: *** [CMakeFiles/Makefile2:4624: > vendor/flatbuffers/CMakeFiles/flatbuffers.dir/all] Error 2 > make: *** [Makefile:136: all] Error 2 > From: Yurii Chalov -X (ychalov - SOFTSERVE INC at Cisco) > <[email protected] <mailto:[email protected]>> > Sent: Tuesday, March 19, 2024 10:37 AM > To: Ron Jenkins <[email protected] <mailto:[email protected]>> > Cc: Nihal Desai (nihdesai) <[email protected] <mailto:[email protected]>>; > [email protected] <mailto:[email protected]> > Subject: Re: SnortML > CAUTION: This email originated from outside your organization. Exercise caution when opening attachments or clicking links, especially from unknown senders. > Hi Ron! > I looked at the output which you sent before, but I don’t see any > errors, just warnings. Could you please make a build using a command > "sudo make -j$(nproc) install 2>&1 | tee error.log” and send a file > “error.log”. I will see here what’s happening Best wishes Yurii > Chalov > > > On 19 Mar 2024, at 16:33, Ron Jenkins <[email protected] <mailto:[email protected]>> wrote: > ???? From: Nihal Desai (nihdesai) <[email protected] <mailto:[email protected]>> > Sent: Tuesday, March 19, 2024 10:25 AM > To: Ron Jenkins <[email protected] <mailto:[email protected]>>; > [email protected] <mailto:[email protected]> > Cc: Yurii Chalov -X (ychalov - SOFTSERVE INC at Cisco) > <[email protected] <mailto:[email protected]>> > Subject: Re: SnortML > CAUTION: This email originated from outside your organization. Exercise caution when opening attachments or clicking links, especially from unknown senders. > + Yuri > -- > V/r > Nihal N. Desai > From: Ron Jenkins <[email protected] <mailto:[email protected]>> > Date: Monday, March 18, 2024 at 7:38 PM > To: Nihal Desai (nihdesai) <[email protected] <mailto:[email protected]>>, > [email protected] <mailto:[email protected]> <[email protected] <mailto:[email protected]>> > Subject: RE: SnortML > Please see below. > cmake version 3.28.3 > c++ (Ubuntu 13.2.0-17ubuntu2) 13.2.0 > Thanks > In member function ‘_Tp* std::__new_allocator<_Tp>::allocate(size_type, const void*) [with _Tp = unsigned char]’, > inlined from ‘static _Tp* std::allocator_traits<std::allocator<_CharT> >::allocate(allocator_type&, size_type) [with _Tp = unsigned char]’ at /usr/include/c++/13/bits/alloc_traits.h:482:28, > inlined from ‘std::_Vector_base<_Tp, _Alloc>::pointer std::_Vector_base<_Tp, _Alloc>::_M_allocate(std::size_t) [with _Tp = unsigned char; _Alloc = std::allocator<unsigned char>]’ at /usr/include/c++/13/bits/stl_vector.h:378:33, > inlined from ‘void std::vector<_Tp, _Alloc>::_M_range_insert(iterator, _ForwardIterator, _ForwardIterator, std::forward_iterator_tag) [with _ForwardIterator = const unsigned char*; _Tp = unsigned char; _Alloc = std::allocator<unsigned char>]’ at /usr/include/c++/13/bits/vector.tcc:805:40, > inlined from ‘std::vector<_Tp, _Alloc>::iterator std::vector<_Tp, _Alloc>::insert(const_iterator, _InputIterator, _InputIterator) [with _InputIterator = const unsigned char*; <template-parameter-2-2> = void; _Tp = unsigned char; _Alloc = std::allocator<unsigned char>]’ at /usr/include/c++/13/bits/stl_vector.h:1483:19, > inlined from ‘const uint8_t* flatbuffers::AddFlatBuffer(std::vector<unsigned char>&, const uint8_t*, size_t)’ at /downloads/snort3/libml-1.0.0/vendor/flatbuffers/src/reflection.cpp:365:17: > /usr/include/c++/13/bits/new_allocator.h:151:55: note: at offset [-9223372036854775808, -4] into destination object of size [4, 9223372036854775807] allocated by ‘operator new’ > 151 | return static_cast<_Tp*>(_GLIBCXX_OPERATOR_NEW(__n * sizeof(_Tp))); > | ^ > At global scope: > cc1plus: note: unrecognized command-line option > ‘-Wno-unknown-attributes’ may have been intended to silence earlier > diagnostics > cc1plus: all warnings being treated as errors > make[2]: *** > [vendor/flatbuffers/CMakeFiles/flatbuffers.dir/build.make:104: > vendor/flatbuffers/CMakeFiles/flatbuffers.dir/src/reflection.cpp.o] > Error 1 > make[1]: *** [CMakeFiles/Makefile2:4624: > vendor/flatbuffers/CMakeFiles/flatbuffers.dir/all] Error 2 > make: *** [Makefile:136: all] Error 2 > root@ids-sensor2:/downloads/snort3/libml-1.0.0/build# <mailto:root@ids-sensor2:/downloads/snort3/libml-1.0.0/build> > From: Nihal Desai (nihdesai) <[email protected] <mailto:[email protected]>> > Sent: Monday, March 18, 2024 4:34 PM > To: Ron Jenkins <[email protected] <mailto:[email protected]>>; > [email protected] <mailto:[email protected]> > Subject: Re: SnortML > CAUTION: This email originated from outside your organization. Exercise caution when opening attachments or clicking links, especially from unknown senders. > Hey Ron, > Thanks for reporting the issue. > Can you provide the output of the error? I don’t see it in the screenshot here. > What version of cmake and c++ compiler are you using? > Thanks! > -- > V/r > Nihal N. Desai > From: Snort-users <[email protected] <mailto:[email protected]>> on behalf of > Ron Jenkins via Snort-users <[email protected] <mailto:[email protected]>> > Date: Monday, March 18, 2024 at 8:42 AM > To: [email protected] <mailto:[email protected]> <[email protected] <mailto:[email protected]>> > Subject: [Snort-users] SnortML > Good morning > Is there any document on installing from source released yet? I am also getting the below when performing ‘make -j$(nproc) install’. > Thank you! > <image001.png> > Ron Jenkins (Owner / Senior Architect / Cyber Security Consultant) > RMJ Consulting, LLC. " Supporting Companies with their Technology needs" > 11715 Bricksome Ave STE B-7 > Baton Rouge, LA 70816 > Direct. 225-448-5214 Ext #101 > Cell. 225-931-1632 > Web. http://www.rmjconsulting.net <http://www.rmjconsulting.net/> > Log Siphon. http://www.logsiphon.com <http://www.logsiphon.com/> > Linkedin. www.linkedin.com/in/ronmjenkins/ <http://www.linkedin.com/in/ronmjenkins/> > Twitter: www.twitter.com/RMJConsulting <http://www.twitter.com/RMJConsulting> > Facebook: www.facebook.com/rmjcsconsulting <http://www.facebook.com/rmjcsconsulting> > PRIVILEGED & CONFIDENTIAL COMMUNICATION: > The information contained in this transmission may be privileged, confidential, and exempt from disclosure under applicable law. It is intended only for the use of the intended recipient. If you are not the intended recipient, you are hereby on notice that any unauthorized disclosure, dissemination, distribution, duplication, or taking any action in reliance on the contents of the electronically transmitted materials or contents of this communication is strictly prohibited. If you have received this communication in error, please contact the sender by reply e-mail and destroy all copies of the original message. > PRIVILEGED & CONFIDENTIAL COMMUNICATION: > The information contained in this transmission may be privileged, confidential, and exempt from disclosure under applicable law. It is intended only for the use of the intended recipient. If you are not the intended recipient, you are hereby on notice that any unauthorized disclosure, dissemination, distribution, duplication, or taking any action in reliance on the contents of the electronically transmitted materials or contents of this communication is strictly prohibited. If you have received this communication in error, please contact the sender by reply e-mail and destroy all copies of the original message. > PRIVILEGED & CONFIDENTIAL COMMUNICATION: > The information contained in this transmission may be privileged, confidential, and exempt from disclosure under applicable law. It is intended only for the use of the intended recipient. If you are not the intended recipient, you are hereby on notice that any unauthorized disclosure, dissemination, distribution, duplication, or taking any action in reliance on the contents of the electronically transmitted materials or contents of this communication is strictly prohibited. If you have received this communication in error, please contact the sender by reply e-mail and destroy all copies of the original message. PRIVILEGED & CONFIDENTIAL COMMUNICATION: > The information contained in this transmission may be privileged, confidential, and exempt from disclosure under applicable law. It is intended only for the use of the intended recipient. If you are not the intended recipient, you are hereby on notice that any unauthorized disclosure, dissemination, distribution, duplication, or taking any action in reliance on the contents of the electronically transmitted materials or contents of this communication is strictly prohibited. If you have received this communication in error, please contact the sender by reply e-mail and destroy all copies of the original message. > > PRIVILEGED & CONFIDENTIAL COMMUNICATION: > The information contained in this transmission may be privileged, confidential, and exempt from disclosure under applicable law. It is intended only for the use of the intended recipient. If you are not the intended recipient, you are hereby on notice that any unauthorized disclosure, dissemination, distribution, duplication, or taking any action in reliance on the contents of the electronically transmitted materials or contents of this communication is strictly prohibited. If you have received this communication in error, please contact the sender by reply e-mail and destroy all copies of the original message. > > PRIVILEGED & CONFIDENTIAL COMMUNICATION: > The information contained in this transmission may be privileged, confidential, and exempt from disclosure under applicable law. It is intended only for the use of the intended recipient. If you are not the intended recipient, you are hereby on notice that any unauthorized disclosure, dissemination, distribution, duplication, or taking any action in reliance on the contents of the electronically transmitted materials or contents of this communication is strictly prohibited. If you have received this communication in error, please contact the sender by reply e-mail and destroy all copies of the original message. > > PRIVILEGED & CONFIDENTIAL COMMUNICATION: > The information contained in this transmission may be privileged, confidential, and exempt from disclosure under applicable law. It is intended only for the use of the intended recipient. If you are not the intended recipient, you are hereby on notice that any unauthorized disclosure, dissemination, distribution, duplication, or taking any action in reliance on the contents of the electronically transmitted materials or contents of this communication is strictly prohibited. If you have received this communication in error, please contact the sender by reply e-mail and destroy all copies of the original message. > > _______________________________________________ > Snort-users mailing list > [email protected] <mailto:[email protected]> > Go to this URL to change user options or unsubscribe: > https://lists.snort.org/mailman/listinfo/snort-users > > To unsubscribe, send an email to: > [email protected] <mailto:[email protected]> > > Please visit http://blog.snort.org <http://blog.snort.org/> to stay current on all the latest Snort news! > > Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette > PRIVILEGED & CONFIDENTIAL COMMUNICATION: > The information contained in this transmission may be privileged, confidential, and exempt from disclosure under applicable law. It is intended only for the use of the intended recipient. If you are not the intended recipient, you are hereby on notice that any unauthorized disclosure, dissemination, distribution, duplication, or taking any action in reliance on the contents of the electronically transmitted materials or contents of this communication is strictly prohibited. If you have received this communication in error, please contact the sender by reply e-mail and destroy all copies of the original message. > > _______________________________________________ > Snort-users mailing list > [email protected] <mailto:[email protected]> > Go to this URL to change user options or unsubscribe: > https://lists.snort.org/mailman/listinfo/snort-users > > To unsubscribe, send an email to: > [email protected] <mailto:[email protected]> > > Please visit http://blog.snort.org <http://blog.snort.org/> to stay current on all the latest Snort news! > > Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette