Home page logo

snort logo Snort mailing list archives

Re: Unable to create stub so rules files
From: "C. L. Martinez" <carlopmart () gmail com>
Date: Tue, 27 Nov 2012 14:10:21 +0000

On Tue, Nov 27, 2012 at 10:51 AM, C. L. Martinez <carlopmart () gmail com> wrote:
On Tue, Nov 27, 2012 at 10:43 AM, Peter Bates <peter.bates () ucl ac uk> wrote:
Hash: SHA1

Hello all

On 27/11/2012 10:25, C. L. Martinez wrote:
ERROR: /data/config/etc/idpsnort01//data/config/etc/idpsnort01/so_rules/bad-traffic.rules(0)
Unable to open rules file
No such file or directory.

The above files are missing.
Not so sure why it appears to be using the directory twice instead
of just the once as defined in your conf:

var CONF_PATH /data/config/etc/idpsnort01
var SO_RULE_PATH $CONF_PATH/so_rules

Personally I used PulledPork to manage my rules and SOs and then just have

include $RULE_PATH/snort.rules
include $RULE_PATH/so_rules.rules

Instead of include's for all the seperate files.

Thanks Peter, I have tried with pulledpork too, and same error appears ...

Any idea why my conf it doesn't works??

Monitor your physical, virtual and cloud infrastructure from a single
web console. Get in-depth insight into apps, servers, databases, vmware,
SAP, cloud infrastructure, etc. Download 30-day Free Trial.
Pricing starts from $795 for 25 servers or applications!
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:

Please visit http://blog.snort.org to stay current on all the latest Snort news!

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]