Summary: | net-analyzer/snort 2.9.4.6 needs explicit parameter to find daq | ||
---|---|---|---|
Product: | Gentoo Linux | Reporter: | mike <michael.stahn.42> |
Component: | Current packages | Assignee: | Patrick Lauer <patrick> |
Status: | CONFIRMED --- | ||
Severity: | minor | CC: | alexanderyt, jstein, kumba, msava, netmon, staff, trekie |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | All | ||
Whiteboard: | |||
Package list: | Runtime testing required: | --- |
Description
mike
2011-04-15 21:43:08 UTC
Per the post install message... elog "The core DQA libraries are installed in /usr/$(get_libdir)/. The libraries" elog "for the individual DAQ modules (afpacket,pcap,dump) are installed in" elog "/usr/$(get_libdir)/daq. To use these you will need to add the following" elog "lines to your snort.conf:" elog elog "config daq: <DAQ module>" elog "config daq_mode: <mode>" elog "config daq_dir: /usr/$(get_libdir)/daq" You need to include the "config daq_dir:" in your config file or edit the conf.d file and include --daq-dir in SNORT_OPTS. Most of the options in the current conf.d file will be included by default in the snort.conf that ships with snort (in the next version I believe). When they are included in snort.conf they will be removed from conf.d. (In reply to comment #1) > Per the post install message... > > elog "The core DQA libraries are installed in /usr/$(get_libdir)/. The > libraries" > elog "for the individual DAQ modules (afpacket,pcap,dump) are installed in" > elog "/usr/$(get_libdir)/daq. To use these you will need to add the > following" > elog "lines to your snort.conf:" hm k this was a little confusing because there is no snort.conf but a snort.conf.distrib..I suppose this is the one. This is not fixed IMHO. I've got this in /etc/snort.conf: config daq: afpacket config daq_dir: /usr/lib64/daq config daq_mode: passive This fails: # /etc/init.d/snort start * Caching service dependencies ... [ ok ] * Use of the opts variable is deprecated and will be * removed in the future. * Please use extra_commands, extra_started_commands or extra_stopped_commands. * Starting snort ... [ !! ] * ERROR: snort failed to start # snort Running in packet dump mode --== Initializing Snort ==-- Initializing Output Plugins! ERROR: Can't find pcap DAQ! Fatal Error, Quitting.. But This works: snort --daq-dir /usr/lib/daq/ The same problem exists with 2.9.1, 2.9.2.3 Same in 2.9.4.6 and while we are at it: The dependency is too low, 0.6.2 is not enough: # snort -v --daq-dir /usr/lib/daq Running in packet dump mode --== Initializing Snort ==-- Initializing Output Plugins! pcap DAQ configured to passive. The DAQ version does not support reload. this still happens with daq-2.0.0 version. Does this happen only when running Snort via the /etc/init.d route, or also when running as an unprivileged user? Cause I checked my local user copy of my snort conf, and with all three daq config lines present, Snort can find and run daq w/o issues. I use these three for reading in local libpcap files: config daq: pcap config daq_mode: read-file config daq_dir: /home/<user>/snort/lib/daq/ I'll try to fix the daq version dep as well. daq has been updated to 2.0.2, and newer Snort ebuilds have been added to the tree. Please check to see if this problem still exists or not. If it is, please attach your Snort configuration file. bump, still an issue, i solved and resolved this on my own..... see notes https://forums.gentoo.org/viewtopic-t-984762-highlight-.html snort fails to pull in net-libs/libnetfilter_queue on top of that, its 'all' interface monitoring is not working. (In reply to three sixes from comment #9) > bump, still an issue, i solved and resolved this on my own..... see notes > > https://forums.gentoo.org/viewtopic-t-984762-highlight-.html > > snort fails to pull in net-libs/libnetfilter_queue > > on top of that, its 'all' interface monitoring is not working. It looks like Snort isn't itself responsible for pulling in the net-libs/libnetfilter_queue library. You have to make sure to set 'nfq' in your USE flags and re-merge net-libs/daq, which contains the libnetfilter_queue dependency. I am not sure about the use of the "all" interface not working. That sounds like a problem upstream (possibly with the upstream-provided configuration), so you may have to ask on the snort-users ML for more info on that. If you feel this is a problem with the ebuild, please open a new bug specific to this issue. Additionally, Snort-2.9.6.0 is in the tree, so test against that, too, if you can. |