daq var is a problem i was copy past daq var from a pdf about snort3 inline multiple packet processing

Dorian ROSSE via Snort-users <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general,gmane.comp.security.ids.snort.sigs
Message-ID <DB7P193MB0346107E9C2C59733C0254D9DAF89@DB7P193MB0346.EURP193.PROD.OUTLOOK.COM>
hello,


daq var is a problem i was copy past daq var from a pdf about snort3 inline multiple packet processing,

'''sudo /usr/local/bin/snort -c /usr/local/etc/snort/snort.lua --daq-dir /usr/local/lib/daq --daq dump --daq-var lb_total=4 --daq-var fanout_type=hash -s 65535 -k all -l /var/log/snort -i enp0s25 --daq-var lb_id=1 -i wlp3s0 --daq-var lb_id=2 -z 2 -m 0x1b
[sudo] Mot de passe de dorianrosse :
Désolé, essayez de nouveau.
[sudo] Mot de passe de dorianrosse :
--------------------------------------------------
o")~   Snort++ 3.1.21.0
--------------------------------------------------
Loading /usr/local/etc/snort/snort.lua:
Loading snort_defaults.lua:
Finished snort_defaults.lua:
Loading file_magic.lua:
Finished file_magic.lua:
Loading inline.lua:
Finished inline.lua:
Loading talos.lua:
Finished talos.lua:
active
alerts
daq
decode
host_cache
host_tracker
hosts
packets
process
search_engine
so_proxy
back_orifice
dnp3
dns
imap
iec104
modbus
netflow
normalizer
pop
sip
ssh
ssl
telnet
dce_smb
dce_udp
dce_http_proxy
dce_http_server
gtp_inspect
smtp
ftp_client
ftp_data
http2_inspect
file_id
file_policy
detection
wizard
alert_talos
stream_ip
stream_icmp
binder
reputation
    Processing blocklist file /usr/local/etc/snort/../lists/default.blocklist
    Reputation entries loaded: 1216, invalid: 0, re-defined: 0 (from file /usr/local/etc/snort/../lists/default.blocklist)
appid
http_inspect
ftp_server
port_scan
dce_tcp
rpc_decode
arp_spoof
stream_file
stream_user
stream_udp
stream_tcp
references
classifications
stream
profiler
alert_json
snort
ERROR: /usr/local/etc/snort/snort.lua: snort.--daq-var is invalid
trace
ips
output
network
Finished /usr/local/etc/snort/snort.lua:
--------------------------------------------------
rule counts
       total rules loaded: 600
            builtin rules: 600
            option chains: 600
            chain headers: 1
--------------------------------------------------
port rule counts
             tcp     udp    icmp      ip
     any     600       0       0       0
   total     600       0       0       0
--------------------------------------------------
ips policies rule stats
              id  loaded  shared enabled    file
               0     600       0     600    /usr/local/etc/snort/snort.lua
--------------------------------------------------
dump:pcap DAQ configured to inline.
FATAL: see prior 1 errors (0 warnings)
Fatal Error, Quitting..
'''

thanks you in advance to help myself pass this errors,

regards.


Dorian ROSSE.

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.