You need to download the so rules for your distro or compile them yourself on your box. Here is a quick guide from snort on how to do it.
Your error is telling you there are no rules in the directory listed.
Hello, I manage to start snort
but i have nothing in base.
nada, zero entry.
where do i start looking ?
here is the requested screenshot.
let me know
I see nothing wrong.
You either have to hit snort with something or wait, but your sensor is registering (the 0/1 line) and I can see no problem with your installation.
tried ssh failure
and get any alert
Last edited by Zapisto; March 15th, 2010 at 09:45 PM.
Generating snort alerts is grey hat at best and as such is beyond what we support on these forums.
A simple google search will answer your question on how to generate a snort alert as will time.
The most important thing is that you see your sensor in base, the line reads "0/1"
The 0 means you have had no alerts, the 1 means base is connected to snort.
Everything is working as expected, beyond that you will need to read.
thnaks a lot