-
Notifications
You must be signed in to change notification settings - Fork 12
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
SO rule XXXX not loaded #46
Comments
Hello, |
I failed to mention that this is on a RPi4 with Ubuntu could the distro value be a problem? Thanks! |
i've deleted the pp.conf from your comment since it includes your oinkcode, and the pulledpork output with the -v flag contains all the info we need. |
Thanks! (I had masked some of the oink code) When I comment out line 19 it still gives an error but reduces the error to 250. |
So the Ubuntu-x64 pre-compiled rules won't work with the RPI, because those compiled rules are for the x64 architecture, and the RPI uses the ARM architecture. |
When i try to run snort using
snort -c /usr/local/etc/snort/snort.lua --plugin-path /usr/local/etc/so_rules/
I get the error
ERROR: ../rules/pulledpork.rules:19 SO rule xxxx not loaded.
pulledpork.conf has following option
community_ruleset = false
registered_ruleset = false
LightSPD_ruleset = true
oinkcode = b1c731eb74a69caxxxxxxxxxxx0811baa
snort_blocklist = true
et_blocklist = true
blocklist_path = /usr/local/etc/lists/default.blocklist
snort_path = /usr/local/bin/snort
ips_policy = balanced
rule_mode = simple
rule_path = /usr/local/etc/rules/pulledpork.rules
local_rules = /usr/local/etc/rules/local.rules
....
....
SO rules directory is populated
Any help appreciaed
The text was updated successfully, but these errors were encountered: