starting up snort results in: Running in packet dump mode --== Initializing Snort ==-- Initializing Output Plugins! ERROR: Can't find pcap DAQ! Fatal Error, Quitting.. This can be fixed by explicitly giving the daq-directory with "--daq-dir /usr/lib/daq/". Cant this be set at installation via configuration? Reproducible: Always Steps to Reproduce: 1. startup snort Actual Results: snort reports: ERROR: Can't find pcap DAQ! Expected Results: no errors Portage 2.1.9.42 (default/linux/x86/10.0, gcc-4.4.5, glibc-2.11.3-r0, 2.6.36-gentoo-r8 i686) ================================================================= System uname: Linux-2.6.36-gentoo-r8-i686-Intel-R-_Core-TM-2_Duo_CPU_L9400_@_1.86GHz-with-gentoo-1.12.14 Timestamp of tree: Fri, 15 Apr 2011 12:45:01 +0000 ccache version 2.4 [enabled] app-shells/bash: 4.1_p9 dev-java/java-config: 2.1.11-r3 dev-lang/python: 2.6.6-r2, 3.1.3-r1 dev-util/ccache: 2.4-r9 dev-util/cmake: 2.8.1-r2 sys-apps/baselayout: 1.12.14-r1 sys-apps/sandbox: 2.4 sys-devel/autoconf: 2.13, 2.65-r1 sys-devel/automake: 1.9.6-r3, 1.10.3, 1.11.1 sys-devel/binutils: 2.20.1-r1 sys-devel/gcc: 4.4.5 sys-devel/gcc-config: 1.4.1 sys-devel/libtool: 2.2.10 sys-devel/make: 3.81-r2 sys-kernel/linux-headers: 2.6.36.1 virtual/os-headers: 0 ACCEPT_KEYWORDS="x86" ACCEPT_LICENSE="* -@EULA" CBUILD="i686-pc-linux-gnu" CFLAGS="-O2 -march=native -pipe" CHOST="i686-pc-linux-gnu" CONFIG_PROTECT="/etc /usr/share/gnupg/qualified.txt /usr/share/maven-bin-3.0/conf /usr/share/openvpn/easy-rsa /var/lib/hsqldb" CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/env.d /etc/env.d/java/ /etc/fonts/fonts.conf /etc/gconf /etc/php/apache2-php5.3/ext-active/ /etc/php/cgi-php5.3/ext-active/ /etc/php/cli-php5.3/ext-active/ /etc/revdep-rebuild /etc/sandbox.d /etc/terminfo /etc/texmf/language.dat.d /etc/texmf/language.def.d /etc/texmf/updmap.d /etc/texmf/web2c" CXXFLAGS="-O2 -march=native -pipe" DISTDIR="/usr/portage/distfiles" FEATURES="assume-digests binpkg-logs ccache distlocks fixlafiles fixpackages news parallel-fetch protect-owned sandbox sfperms strict unknown-features-warn unmerge-logs unmerge-orphans userfetch" FFLAGS="" LDFLAGS="-Wl,-O1 -Wl,--as-needed" MAKEOPTS="-j3" PKGDIR="/usr/portage/packages" PORTAGE_CONFIGROOT="/" PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages" PORTAGE_TMPDIR="/var/tmp" PORTDIR="/usr/portage" PORTDIR_OVERLAY="/var/lib/layman/fordfrog" SYNC="rsync://rsync1.de.gentoo.org/gentoo-portage" USE="X acl acpi alsa bash-completion berkdb bzip2 cli cracklib crypt cups cxx dri dri2 fortran gdbm gpm iconv ipv6 libv4l2 mmx modules mudflap ncurses nls nptl nptlonly opengl openmp pam pcre perl pppd python qt3support qt4 readline sdl session sse sse2 sse3 ssl ssse3 sysfs tcpd threads unicode v4l v4l2 x86 xorg zlib" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1 emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci" ALSA_PCM_PLUGINS="adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mmap_emul mulaw multi null plug rate route share shm softvol" APACHE2_MODULES="actions alias auth_basic authn_alias authn_anon authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache cgi cgid dav dav_fs dav_lock deflate dir disk_cache env expires ext_filter file_cache filter headers include info log_config logio mem_cache mime mime_magic negotiation rewrite setenvif speling status unique_id userdir usertrack vhost_alias" CAMERAS="ptp2" COLLECTD_PLUGINS="df interface irq load memory rrdtool swap syslog" ELIBC="glibc" GPSD_PROTOCOLS="ashtech aivdm earthmate evermore fv18 garmin garmintxt gpsclock itrax mtk3301 nmea ntrip navcom oceanserver oldstyle oncore rtcm104v2 rtcm104v3 sirf superstar2 timing tsip tripmate tnt ubx" INPUT_DEVICES="keyboard mouse evdev" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" PHP_TARGETS="php5-3" RUBY_TARGETS="ruby18" USERLAND="GNU" VIDEO_CARDS="intel" XTABLES_ADDONS="quota2 psd pknock lscan length2 ipv4options ipset ipp2p iface geoip fuzzy condition tee tarpit sysrq steal rawnat logmark ipmark dhcpmac delude chaos account" Unset: CPPFLAGS, CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LANG, LC_ALL, LINGUAS, PORTAGE_BUNZIP2_COMMAND, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS
Per the post install message... elog "The core DQA libraries are installed in /usr/$(get_libdir)/. The libraries" elog "for the individual DAQ modules (afpacket,pcap,dump) are installed in" elog "/usr/$(get_libdir)/daq. To use these you will need to add the following" elog "lines to your snort.conf:" elog elog "config daq: <DAQ module>" elog "config daq_mode: <mode>" elog "config daq_dir: /usr/$(get_libdir)/daq" You need to include the "config daq_dir:" in your config file or edit the conf.d file and include --daq-dir in SNORT_OPTS. Most of the options in the current conf.d file will be included by default in the snort.conf that ships with snort (in the next version I believe). When they are included in snort.conf they will be removed from conf.d.
(In reply to comment #1) > Per the post install message... > > elog "The core DQA libraries are installed in /usr/$(get_libdir)/. The > libraries" > elog "for the individual DAQ modules (afpacket,pcap,dump) are installed in" > elog "/usr/$(get_libdir)/daq. To use these you will need to add the > following" > elog "lines to your snort.conf:" hm k this was a little confusing because there is no snort.conf but a snort.conf.distrib..I suppose this is the one.
This is not fixed IMHO. I've got this in /etc/snort.conf: config daq: afpacket config daq_dir: /usr/lib64/daq config daq_mode: passive This fails: # /etc/init.d/snort start * Caching service dependencies ... [ ok ] * Use of the opts variable is deprecated and will be * removed in the future. * Please use extra_commands, extra_started_commands or extra_stopped_commands. * Starting snort ... [ !! ] * ERROR: snort failed to start # snort Running in packet dump mode --== Initializing Snort ==-- Initializing Output Plugins! ERROR: Can't find pcap DAQ! Fatal Error, Quitting.. But This works: snort --daq-dir /usr/lib/daq/
The same problem exists with 2.9.1, 2.9.2.3
Same in 2.9.4.6 and while we are at it: The dependency is too low, 0.6.2 is not enough: # snort -v --daq-dir /usr/lib/daq Running in packet dump mode --== Initializing Snort ==-- Initializing Output Plugins! pcap DAQ configured to passive. The DAQ version does not support reload.
this still happens with daq-2.0.0 version.
Does this happen only when running Snort via the /etc/init.d route, or also when running as an unprivileged user? Cause I checked my local user copy of my snort conf, and with all three daq config lines present, Snort can find and run daq w/o issues. I use these three for reading in local libpcap files: config daq: pcap config daq_mode: read-file config daq_dir: /home/<user>/snort/lib/daq/ I'll try to fix the daq version dep as well.
daq has been updated to 2.0.2, and newer Snort ebuilds have been added to the tree. Please check to see if this problem still exists or not. If it is, please attach your Snort configuration file.
bump, still an issue, i solved and resolved this on my own..... see notes https://forums.gentoo.org/viewtopic-t-984762-highlight-.html snort fails to pull in net-libs/libnetfilter_queue on top of that, its 'all' interface monitoring is not working.
(In reply to three sixes from comment #9) > bump, still an issue, i solved and resolved this on my own..... see notes > > https://forums.gentoo.org/viewtopic-t-984762-highlight-.html > > snort fails to pull in net-libs/libnetfilter_queue > > on top of that, its 'all' interface monitoring is not working. It looks like Snort isn't itself responsible for pulling in the net-libs/libnetfilter_queue library. You have to make sure to set 'nfq' in your USE flags and re-merge net-libs/daq, which contains the libnetfilter_queue dependency. I am not sure about the use of the "all" interface not working. That sounds like a problem upstream (possibly with the upstream-provided configuration), so you may have to ask on the snort-users ML for more info on that. If you feel this is a problem with the ebuild, please open a new bug specific to this issue. Additionally, Snort-2.9.6.0 is in the tree, so test against that, too, if you can.