[Snort-users] Run as user?

Erek Adams erek at ...950...
Wed Apr 2 22:20:30 EST 2003


On Thu, 3 Apr 2003, Joe Hill wrote:

> sorry, what I meant was to actually run snort without first su'ing to root.

Not unless you login as root.

> is there any way to do this and have access to eth0?

Only if you change permissions on your interface device so that the snort
user/group can access it.

> when I run snort, it says it will write to /var/log/snort, but I find no such directory or file.

mkdir -p /var/log/snort

> ie. to kill the process?

No.  Sending snort a HUP will force it to 'restart' and 'reload'.  If you
change permissions on the device, you will be able to HUP it.

> I must admit, I only went back about 20 pages...;)

http://marc.theaimsgroup.com/?l=snort-users&r=1&w=2

Has a rather nice search feature.  :)

-----
Erek Adams

   "When things get weird, the weird turn pro."   H.S. Thompson




More information about the Snort-users mailing list