AW: [Snort-users] Snort+IDMEF...need help!

Poppi, Sandro Sandro.Poppi at ...3316...
Mon Sep 29 15:07:27 EDT 2003

Take a look at where I provide a new

Hi all,
I tried to bring my snort + idmef up.
But, so far, snort process was dead with this error 
Sep 28 16:28:00 biff snort: FATAL ERROR: IDMEF: cannot output messages on a
NULL facility
I'm runing snort-2.0.2 with IDMEF XML output plugin for Snort, version
I can complie both of them without problem. This is the snort's
configuration line...
$ ./configure --prefix=/usr/local/snort --mandir=/usr/local/man
The following alert is received and snort is dead.... (/var/log/snort/alert)
[**] [1:1411:3] SNMP public access udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
09/29-00:11:49.034901 ->
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:117 DF
Len: 89
[Xref =>][Xref
<][Xref>  => ht
tp://][Xref =>
http://cve.mi <http://cve.mi>]

and snort is dead!
This is the IDMEF setting in my snort.conf file.
output idmef: $HOME_NET logto=/var/log/snort/idmef_alerts.log
rt/etc/idmef-message.dtd analyzerid=IDS1 output=alert name=biff
default=ascii in
Do you  have any idea where I stuck?
Prachid T.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <>

More information about the Snort-users mailing list