Snorby and snort are not running

594 views
Skip to first unread message

Abner Ortiz

unread,
Mar 9, 2015, 2:00:20 AM3/9/15
to securit...@googlegroups.com
i just installed it into my old computer with 4gb Ram and i want to test it. I followed all the videos and set ups correctly and when i open snorby site it does not show any logs. 0 in everything.

when i run the command snort -i status it shows

--== Initializing Snort ==--
Initializing Output Plugins!
pcap DAQ configured to passive.
Acquiring network traffic from "status".
ERROR: Can't start DAQ (-1) - socket: Operation not permitted!
Fatal Error, Quitting..


i guess some libraries are missing. i am not sure or maybe permissions. thank you. iI also would like to know what is the root password thx. and when i run the barnyard2 status it shows everything 0. nothing to write into the database.

What is it missing?

thank you

Heine Lysemose

unread,
Mar 9, 2015, 3:49:33 AM3/9/15
to securit...@googlegroups.com
Hi

Try running 'sudo snort -i status'

For further troubleshooting please attach the output from sudo sostat-redacted

Thanks,
Lysemose


--
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at http://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/d/optout.

Abner Ortiz

unread,
Mar 20, 2015, 7:53:00 PM3/20/15
to securit...@googlegroups.com
I am using the root. so it worked, but the snort is not running, even using ps aux | snort

Doug Burks

unread,
Mar 20, 2015, 8:06:06 PM3/20/15
to securit...@googlegroups.com
Please attach the output of:
sudo sostat-redacted
--
Doug Burks
Need Security Onion Training or Commercial Support?
http://securityonionsolutions.com
Reply all
Reply to author
Forward
0 new messages