-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Description
Hello Eric I am trying to troubleshoot my unified 2 from snort.
Here is some info.
- The specified unified 2 log is not being created.
- Instead I get the snort.log.date (tcpdump) default and alerts.
- snort.conf - output unified2: filename internal.u2, limit 128, vlan_event_types
- running snort with sudo /usr/local/bin/snort -D -q -i eth3 -F /etc/snort/internalbpf.filter -c /usr/src/snort-2.9.8.0/etc/snort.conf.internal -u snort
- No errors or warnings when grep from /var/log/messages
- Running RHEL 6
- Installed and compiled from source
- Snort has rwx for /var/log/snort
- Deleted all logs
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels