,

I have created a unix socket (TCP as well as UDP). I have tested it with a client and it works well. When I try to send alert to unix socket via snort I do not receive any alert. I have uncomment "alert_sfsocket = { }" in snort.lua config file and also used -A alert_unixsock. If i use -L dump it shows alerts on console.

command on terminal:   sudo snort -i ens33 -c ~username/snort_src/snort3/lua/snort.lua -R ~usernamer/snort_src/snort3/lua/snort3-community.rules -A alert_unixsock -l ~username/tmp.

Kindly guide me what else I have to configure so that I receive alerts on unix socket.

Thanks.

More Syed Shabbar Raza Zaidi's questions See All
Similar questions and discussions