[Snort-users] question

Stephen Gantz stephen.gantz at ...16854...
Wed May 6 17:52:43 EDT 2015


Also make sure you have the preprocessor rules enabled in Step #8 of snort.conf. They are commented out by default so you need to un-comment at least preprocessor.rules and decoder.rules. 

Dr. Stephen D. Gantz
CISSP-ISSAP, CEH, CGEIT, CRISC, CIPP/G, C|CISO
Professor of Information Assurance
The Graduate School
University of Maryland University College
stephen.gantz at ...16854...

> On May 6, 2015, at 4:22 PM, Al Lewis (allewi) <allewi at ...589...> wrote:
> 
> Hello,
>  
> Are running snort without any preprocessors enabled. To run in IDS mode you need a conf file with some preprocessors enabled.
>  
> http://manual.snort.org/node6.html
>  
>  
>  
>  
> Albert Lewis
> QA Software Engineer
> SOURCEfire, Inc. now part of Cisco
> 9780 Patuxent Woods Drive
> Columbia, MD 21046 
> Phone: (office) 443.430.7112
> Email: allewi at ...589... 
>  
> From: John Mummery [mailto:jmummery.student at ...11827...] 
> Sent: Wednesday, May 06, 2015 2:08 PM
> To: snort-users at lists.sourceforge.net
> Subject: [Snort-users] question
>  
> Hi! What does this mean and how do I fix it?  "Warning: No preprocessors configured for policy 0."
> ------------------------------------------------------------------------------
> One dashboard for servers and applications across Physical-Virtual-Cloud 
> Widest out-of-the-box monitoring support with 50+ applications
> Performance metrics, stats and reports that give you Actionable Insights
> Deep dive visibility with transaction tracing using APM Insight.
> http://ad.doubleclick.net/ddm/clk/290420510;117567292;y
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users
> 
> Please visit http://blog.snort.org to stay current on all the latest Snort news!
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20150506/793cc35d/attachment.html>


More information about the Snort-users mailing list