-> the user snort run as is nobody but should be snort in /etc/conf.d/snort -> the log directory /var/log/snort (by default) is not automatically created nor by snort, nor by the ebuild. -> Also in /etc/conf.d/snort, snort does not listen on every interface by default, so may be changing the last line by (lamer@gentoo.org suggested handling this in /etc/snort/snort.conf, but it is currently only listening on one interface, and I would think this option to be better placed in the conf.d/snort...) : # This pulls in the options above SNORT_OPTS="-D -s -u snort -i any -dev -l $LOGDIR -h $NETWORK -c $CONF" would be wise or # This tell snort which interface to listen on (any for every interface) IFACE=eth0 # This pulls in the options above SNORT_OPTS="-D -s -u snort -i $IFACE -dev -l $LOGDIR -h $NETWORK -c $CONF" kang
Fixed, thanks for finding this!