Snort mailing list archives
There is no /var/log/snort/alert file
From: "d_greenjr" <d_greenjr () hotmail com>
Date: Thu, 15 Jan 2004 09:46:33 -0500
OS: FreeBSD 5.1
Snort ver: 2.1.0 (Build 9)
Problem:
1) No "alert" file was created in /var/log/snort/
2) snort alerts are being reported to the console (which is undesired)
Details:
-snort is running currently in daemon mode with the follwing command in startup script:
"/usr/local/bin/snort -i rl0 -c /usr/local/etc/snort.conf -l /var/log/snort -u snortman -g snortman -D > /dev/nell
&& echo -n ' snort' "
- /var/log/snort permissions are set to drwxr-xr-x snortman snortman
-my logging line in snort.conf reads: " output alert_syslog: LOG_AUTH LOG_ALERT"
-snort is operational and is creating directories under /var/log/snort/<ipaddr>
Current thread:
- There is no /var/log/snort/alert file d_greenjr (Jan 13)
- <Possible follow-ups>
- There is no /var/log/snort/alert file d_greenjr (Jan 15)
