Snort doesn't stay running



  • Every time Snort updates its rules we need to manually start the service again.  The log says it's restarted, but it is not.  Where else can I look for trouble signs?

    Thanks



  • @ethos101:

    Every time Snort updates its rules we need to manually start the service again.  The log says it's restarted, but it is not.  Where else can I look for trouble signs?

    Thanks

    Look in the system log for clues.  My first suspicion is a disabled preprocessor, and the new rule update suddenly has introduced a dependent rule.  Look for any messages about "unrecognized or unknown rule option" in the system log.

    Did you disable any preprocessors on the PREPROCESSORS tab, or have you left everything at the defaults from the initial installation?

    Bill