edisona / snoge

Automatically exported from code.google.com/p/snoge
1 stars 0 forks source link

Unified mode problems #6

Closed GoogleCodeExporter closed 8 years ago

GoogleCodeExporter commented 8 years ago
Hi Leon,
Running (prerelease) (Debian 4.1.2-25))
Running Snort Version 2.8.5.2 
Running snoge 1.8
running SnortUnified_Perl.20100308

csv example works just fine.

command and error:

./snoge.pl -c unified-example.conf -o snort.alert.1273877058

- Unified mode * Importing functions:
Can't locate SnortUnified/Handlers.pm in @INC (@INC 
contains:  .. /etc/perl /usr/local/lib/perl/5.10.0 /usr/local/share/perl/5.
10.0 /usr/lib/perl5 /usr/share/perl5 /usr/lib/perl/5.10 /usr/share/perl/5.1
0 /usr/local/lib/site_perl . ..) at /usr/lib/perl/5.10/SnortUnified.pm 
line 58.
BEGIN failed--compilation aborted at /usr/lib/perl/5.10/SnortUnified.pm 
line 58.
Compilation failed in require at ./snoge.pl line 187.

TIA for any assistance

Original issue reported on code.google.com by rob.l.di...@gmail.com on 14 May 2010 at 11:27

GoogleCodeExporter commented 8 years ago
Hi Leon,

I figured it out. I had not extract the contents of the snort unified perl.tar 
to the
Build directory. Instead a had the folder in the Build directory.

Thanks,

Original comment by rob.l.di...@gmail.com on 15 May 2010 at 1:12

GoogleCodeExporter commented 8 years ago
Good to hear it's working for you.

Original comment by leon.j.w...@gmail.com on 20 May 2010 at 3:55

GoogleCodeExporter commented 8 years ago
i need to look at the code for the -s option to see whatyou are doing there. i 
am
getting a lot of unknowns. not sure if it is because it appears that the 
directions
are being reversed and/or that one side of the event is internal or what. OR,
geolite, well supposedly isnt as accurate.

I am willing to test this on a very large network. not sure if you are 
interested in
the results or not. not sure if this is a priority project or not. I see that 
you are
working on a pcap extraction tool also. I have some ideas for that also, as 
well as a
big network to test it on.

let me know if you want some beta testers. i can get some interns from the local
college to test and document. ;)

ciao

Original comment by rob.l.di...@gmail.com on 20 May 2010 at 9:41

GoogleCodeExporter commented 8 years ago
Thanks for the offer. Ill contact you offline to continue the thread.
As for the unknown location events, the most likely cause is RFC1918 address's.

Thanks

-Leon

Original comment by leon.j.w...@gmail.com on 21 May 2010 at 8:22

GoogleCodeExporter commented 8 years ago
Thanks for the offer. Ill contact you offline to continue the thread.
As for the unknown location events, the most likely cause is RFC1918 address's.

Thanks

-Leon

Original comment by leon.j.w...@gmail.com on 21 May 2010 at 8:22