Ah, so your ip address is in fact changing rapidly.
Try the variable as suggested i nth econfig file :
use global
variable $<interfacename>_ADDRESS which will be always
# initialized to IP address and netmask of the network interface which you run
# snort at.
so
Code:
var HOME_NET $<interfacename>_ADDRESS
I am not sure if you need to change $<interfacename> to eth0 or not, you will have to try and watch snort for errors as you start it manually.
Code:
/usr/local/bin/snort -c /etc/snort/snort.conf -u snort -g snort
YOU NEED TO START SNORT AS ROOT, so either sudo -i then enter that command.
Bookmarks