Snort mailing list archives

snort.conf - Problem with RULE_PATH & inclide


From: Charlie <ForFun2000 () hotmail com>
Date: Sat, 25 Jul 2015 08:55:40 +0100

Hi
I am using Snort 2.9.7.3 on Linux RaspberryPI2 3.18.11-v7+
I have my black_list.rules file in /usr/local/snort/rules/
snort.conf  is in /usr/local/snort/etc/

Why is Snort always prefixing any include with the path to snort.conf ?

EXAMPLE1:
var RULE_PATH ../rules
include /usr/local/snort/rules/black_list.rules
ERROR: /usr/local/snort/etc//usr/local/snort/rules/black_list.rules(0) 
Unable to open rules file
  "/usr/local/snort/etc//usr/local/snort/rules/black_list.rules": No 
such file or directory.

EXAMPLE2:
var RULE_PATH ../rules
include $RULE_PATH/black_list.rules
ERROR: /usr/local/snort/etc/../rules/black_list.rules(0) Unable to open 
rules file "/usr/local/s
nort/etc/../rules/black_list.rules": No such file or directory.

Any ideas?

------------------------------------------------------------------------------
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: