I found your project and it looks really interesting. I built the server this evening but am unable to sniff on the wire. When I run the
sagan --debug syslog,engine
command I get:
[E] [config-yaml.c, line 1316] Sagan was not compiled with libpcap support!
When installing I added I believe all pre-requisites and all optional softwares. The list installed is:
yum install pcre-devel libyaml-devel liblognorm liblognorm-devel libfastjson libfastjson-devel GeoIP GeoIP-devel GeoIP-data wget libpcap libpcap-devel git autogen gcc clang libtool autoconf autoreconf automake
If its already hit you what I did wrong and if there is other information which will better diagnose, please let me know.
Thanks