<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How to install Snort Intrusion Detection System on Windows</title>
	<atom:link href="http://blog.amarkulo.com/how-to-install-snort-ids-on-windows/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows</link>
	<description>Yet another technical blog about iOS, Windows, Linux, Arduino and everything else</description>
	<lastBuildDate>Wed, 28 Dec 2011 15:05:07 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
	<item>
		<title>By: amar</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-651</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Wed, 14 Dec 2011 14:34:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-651</guid>
		<description>Glad that I could help.

Cheers</description>
		<content:encoded><![CDATA[<p>Glad that I could help.</p>
<p>Cheers</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hans</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-650</link>
		<dc:creator>Hans</dc:creator>
		<pubDate>Wed, 14 Dec 2011 14:33:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-650</guid>
		<description>Excellent, I will try to finish up my install today. Thanks again!</description>
		<content:encoded><![CDATA[<p>Excellent, I will try to finish up my install today. Thanks again!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: amar</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-645</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Wed, 14 Dec 2011 07:23:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-645</guid>
		<description>I think they should without any problem, the only thing changed are new ruleset and eventually some new config options in snort.conf but as we are using default one with removed ssh preprocessor it should work.</description>
		<content:encoded><![CDATA[<p>I think they should without any problem, the only thing changed are new ruleset and eventually some new config options in snort.conf but as we are using default one with removed ssh preprocessor it should work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hans</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-639</link>
		<dc:creator>Hans</dc:creator>
		<pubDate>Tue, 13 Dec 2011 19:39:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-639</guid>
		<description>Another quick question for you Amar. The newest version of Snort is currently at 2.9 something, will these directions work with the newest version too?

I&#039;m looking through the snort.conf now and things seem to be a bit different.  Once again thanks for your time and patience..</description>
		<content:encoded><![CDATA[<p>Another quick question for you Amar. The newest version of Snort is currently at 2.9 something, will these directions work with the newest version too?</p>
<p>I&#8217;m looking through the snort.conf now and things seem to be a bit different.  Once again thanks for your time and patience..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: amar</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-635</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Tue, 13 Dec 2011 18:05:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-635</guid>
		<description>No hard feelings here ;-)

Reason for moderation is that akismet spam filter is down sometimes and then I got loads of spam idiots with replicas of watches, viagra, you name it which I block manually, but all comments from real people are approved directly, good and bad ones.

Glad that you find blog helpful.

Regards
Amar</description>
		<content:encoded><![CDATA[<p>No hard feelings here <img src='http://blog.amarkulo.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>Reason for moderation is that akismet spam filter is down sometimes and then I got loads of spam idiots with replicas of watches, viagra, you name it which I block manually, but all comments from real people are approved directly, good and bad ones.</p>
<p>Glad that you find blog helpful.</p>
<p>Regards<br />
Amar</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hans</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-634</link>
		<dc:creator>Hans</dc:creator>
		<pubDate>Tue, 13 Dec 2011 18:03:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-634</guid>
		<description>I want to apologize for being so hasty with my words. I do understand the spam and wanted to be a man and apologize for being rude. You don&#039;t have to post this, I just wanted you to know i feel like a complete a-hole about it! Have a great day and great blog, best of luck!</description>
		<content:encoded><![CDATA[<p>I want to apologize for being so hasty with my words. I do understand the spam and wanted to be a man and apologize for being rude. You don&#8217;t have to post this, I just wanted you to know i feel like a complete a-hole about it! Have a great day and great blog, best of luck!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: amar</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-633</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Tue, 13 Dec 2011 16:55:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-633</guid>
		<description>Tnx, will do.

Regarding your comments about moderation it&#039;s not moderation that&#039;s issue, it&#039;s spam.</description>
		<content:encoded><![CDATA[<p>Tnx, will do.</p>
<p>Regarding your comments about moderation it&#8217;s not moderation that&#8217;s issue, it&#8217;s spam.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hans</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-630</link>
		<dc:creator>Hans</dc:creator>
		<pubDate>Tue, 13 Dec 2011 16:52:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-630</guid>
		<description>Your link to download snort is dead.. Please update it so people can continue to use your directions and get the correct version of snort.. Thank you..</description>
		<content:encoded><![CDATA[<p>Your link to download snort is dead.. Please update it so people can continue to use your directions and get the correct version of snort.. Thank you..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kashif</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-606</link>
		<dc:creator>Kashif</dc:creator>
		<pubDate>Tue, 15 Nov 2011 17:54:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-606</guid>
		<description>Hi amar,
I want to have SNORT send realtime alerts to my remote syslog server and also send alerts to my email address.
I am using IDS center and it seems like alerts are getting wrtitten on alerts.ids log file but it is neither sending to sysslog nor via email.
Below is config for syslog:

output alert_syslog: host=10.1.1.254:514, LOG_AUTH LOG_ALERT
output alert_fast : alerts.ids

I am using AlertMail and interneting thing is Test Messge works but it doesnt send realtime so something needs to be activated.
Below is the service paramerters I am running:


Snort is currently configured to run as a Windows service using the following
command-line parameters:

     -c C:\Snort\etc\snort.conf -l C:\Snort\log -s -k all -i3

Please advice if I am missing anything.
Many thanks</description>
		<content:encoded><![CDATA[<p>Hi amar,<br />
I want to have SNORT send realtime alerts to my remote syslog server and also send alerts to my email address.<br />
I am using IDS center and it seems like alerts are getting wrtitten on alerts.ids log file but it is neither sending to sysslog nor via email.<br />
Below is config for syslog:</p>
<p>output alert_syslog: host=10.1.1.254:514, LOG_AUTH LOG_ALERT<br />
output alert_fast : alerts.ids</p>
<p>I am using AlertMail and interneting thing is Test Messge works but it doesnt send realtime so something needs to be activated.<br />
Below is the service paramerters I am running:</p>
<p>Snort is currently configured to run as a Windows service using the following<br />
command-line parameters:</p>
<p>     -c C:\Snort\etc\snort.conf -l C:\Snort\log -s -k all -i3</p>
<p>Please advice if I am missing anything.<br />
Many thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: amar</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-589</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Thu, 29 Sep 2011 18:29:31 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-589</guid>
		<description>There isn&#039;t any difference in functionality, linux version has ssh modules as well, but principle is the same.</description>
		<content:encoded><![CDATA[<p>There isn&#8217;t any difference in functionality, linux version has ssh modules as well, but principle is the same.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ali Raza</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-588</link>
		<dc:creator>Ali Raza</dc:creator>
		<pubDate>Thu, 29 Sep 2011 17:12:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-588</guid>
		<description>Is there any difference, feature wise, installing Snort in Windows or Linux?
Thanks</description>
		<content:encoded><![CDATA[<p>Is there any difference, feature wise, installing Snort in Windows or Linux?<br />
Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: amar</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-585</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Wed, 14 Sep 2011 19:00:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-585</guid>
		<description>I&#039;m writing article about it, will publish it soon.</description>
		<content:encoded><![CDATA[<p>I&#8217;m writing article about it, will publish it soon.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bhavin Satashiya</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-584</link>
		<dc:creator>Bhavin Satashiya</dc:creator>
		<pubDate>Wed, 14 Sep 2011 17:49:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-584</guid>
		<description>sir, how the snort are work..will you give information about it.please..</description>
		<content:encoded><![CDATA[<p>sir, how the snort are work..will you give information about it.please..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: amar</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-579</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Wed, 07 Sep 2011 12:23:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-579</guid>
		<description>Hello.

Try to start command prompt as administrator, then you will have more privileges.</description>
		<content:encoded><![CDATA[<p>Hello.</p>
<p>Try to start command prompt as administrator, then you will have more privileges.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GAKURU</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-578</link>
		<dc:creator>GAKURU</dc:creator>
		<pubDate>Sat, 03 Sep 2011 07:47:04 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-578</guid>
		<description>how &#039;re you?
please help me,i try to run snort by this command:&quot;snort -c c:\snort\etc\snort.conf -l c:\Snort\log -i3&quot; on windows 7 ultimate 32bits, then an errors: Unknown preprocessor:&quot;normalize _ipv4&quot; could not create registry key. what can i do to fix this error?
thanks!</description>
		<content:encoded><![CDATA[<p>how &#8216;re you?<br />
please help me,i try to run snort by this command:&#8221;snort -c c:\snort\etc\snort.conf -l c:\Snort\log -i3&#8243; on windows 7 ultimate 32bits, then an errors: Unknown preprocessor:&#8221;normalize _ipv4&#8243; could not create registry key. what can i do to fix this error?<br />
thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: amar</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-568</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Mon, 15 Aug 2011 06:25:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-568</guid>
		<description>I have it installed with Manage Engine Log Analyzer which is free up to 5 hosts. On the same machine snort is installed with -E flag which tells him to log everything in eventlog, then EventLog Analyzer is parsing those logs and I have created special kind of alerts that alerts me in case that some suspicious snort log has been found. You don&#039;t need to know any programming language to implement this. I will write a new blog post how to have everything configured and setup properly.</description>
		<content:encoded><![CDATA[<p>I have it installed with Manage Engine Log Analyzer which is free up to 5 hosts. On the same machine snort is installed with -E flag which tells him to log everything in eventlog, then EventLog Analyzer is parsing those logs and I have created special kind of alerts that alerts me in case that some suspicious snort log has been found. You don&#8217;t need to know any programming language to implement this. I will write a new blog post how to have everything configured and setup properly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: amar</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-567</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Mon, 15 Aug 2011 06:23:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-567</guid>
		<description>Hi!

You can try to start snort from command prompt just to see if it is capturing anything with command snort  -v. In case of error with winpcap you will see directly which error you have. Also you can try running snort -W if you have more than one network interface and then if that is the case run snort with snort -v -i number_of_interface_that_you_got_with_command_before.</description>
		<content:encoded><![CDATA[<p>Hi!</p>
<p>You can try to start snort from command prompt just to see if it is capturing anything with command snort  -v. In case of error with winpcap you will see directly which error you have. Also you can try running snort -W if you have more than one network interface and then if that is the case run snort with snort -v -i number_of_interface_that_you_got_with_command_before.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jonh gape</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-563</link>
		<dc:creator>jonh gape</dc:creator>
		<pubDate>Sat, 13 Aug 2011 16:39:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-563</guid>
		<description>hi! after  installation of winpcap i didn&#039;t  saw anything from network driver, then what can i do?</description>
		<content:encoded><![CDATA[<p>hi! after  installation of winpcap i didn&#8217;t  saw anything from network driver, then what can i do?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GATERA J.Peter</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-559</link>
		<dc:creator>GATERA J.Peter</dc:creator>
		<pubDate>Mon, 25 Jul 2011 18:36:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-559</guid>
		<description>hello!i need to know how i can use snort to detect network intrusion,because i&#039;ve read that it requires the following softwares: Snort, WinPCap, Mysql......, but i do not get how i can implement that system to detect intrusion. i use windows 7 , ultimate 32bits, and i would like to ask if it requires to know at least one of the programming languages?which one is the best?
can i get source code to be used?
thanks!</description>
		<content:encoded><![CDATA[<p>hello!i need to know how i can use snort to detect network intrusion,because i&#8217;ve read that it requires the following softwares: Snort, WinPCap, Mysql&#8230;&#8230;, but i do not get how i can implement that system to detect intrusion. i use windows 7 , ultimate 32bits, and i would like to ask if it requires to know at least one of the programming languages?which one is the best?<br />
can i get source code to be used?<br />
thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: amar</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-558</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Fri, 22 Jul 2011 20:27:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-558</guid>
		<description>You can try to create it with some network scanning tool like Retina or Nessus which is free and see what&#039;s happening.

There are also command switches to start snort from command prompt and to display everything on console so you can check if it is working in real time.</description>
		<content:encoded><![CDATA[<p>You can try to create it with some network scanning tool like Retina or Nessus which is free and see what&#8217;s happening.</p>
<p>There are also command switches to start snort from command prompt and to display everything on console so you can check if it is working in real time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: amar</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-557</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Fri, 22 Jul 2011 20:26:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-557</guid>
		<description>Well first is to run snort as service and to log something, then you need to parse logs and do actions based on log entries.

For example you will have different kind of entries but with priority 1, 2 or 3, where that mean high, moderate or informational priority.

When you detect something with high priority then you can with that software do actions based on alert, I&#039;m using Manage Engine Log Analyzer (which is free up to 5 servers) to manage actions based on log entries.

P.S. After installation you will need to download the latest ruleset for Snort and to apply them as well.</description>
		<content:encoded><![CDATA[<p>Well first is to run snort as service and to log something, then you need to parse logs and do actions based on log entries.</p>
<p>For example you will have different kind of entries but with priority 1, 2 or 3, where that mean high, moderate or informational priority.</p>
<p>When you detect something with high priority then you can with that software do actions based on alert, I&#8217;m using Manage Engine Log Analyzer (which is free up to 5 servers) to manage actions based on log entries.</p>
<p>P.S. After installation you will need to download the latest ruleset for Snort and to apply them as well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GATERA J.Peter</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-556</link>
		<dc:creator>GATERA J.Peter</dc:creator>
		<pubDate>Fri, 22 Jul 2011 19:59:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-556</guid>
		<description>just i need to detect network intrusion</description>
		<content:encoded><![CDATA[<p>just i need to detect network intrusion</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GATERA J.Peter</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-555</link>
		<dc:creator>GATERA J.Peter</dc:creator>
		<pubDate>Fri, 22 Jul 2011 19:23:14 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-555</guid>
		<description>after reading some books, i found that it requires to install winpcap and snort, but after installation of snort i didn&#039;t find anything, so can you give the principal steps to be followed? thanks</description>
		<content:encoded><![CDATA[<p>after reading some books, i found that it requires to install winpcap and snort, but after installation of snort i didn&#8217;t find anything, so can you give the principal steps to be followed? thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: amar</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-553</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Thu, 21 Jul 2011 21:35:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-553</guid>
		<description>Well on site you have how to install it, then you just need to parse logs with some log analyzer and do actions based on log entries.</description>
		<content:encoded><![CDATA[<p>Well on site you have how to install it, then you just need to parse logs with some log analyzer and do actions based on log entries.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GATERA J.Peter</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-552</link>
		<dc:creator>GATERA J.Peter</dc:creator>
		<pubDate>Thu, 21 Jul 2011 20:07:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-552</guid>
		<description>hi! i need to became a snort user,but i do not have enough skills to configure and use it, may i get help and guide for this? i use windows7 ,32bits. thanks!</description>
		<content:encoded><![CDATA[<p>hi! i need to became a snort user,but i do not have enough skills to configure and use it, may i get help and guide for this? i use windows7 ,32bits. thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#187; snort</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-541</link>
		<dc:creator>&#187; snort</dc:creator>
		<pubDate>Fri, 03 Jun 2011 02:13:22 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-541</guid>
		<description>[...] http://blog.amarkulo.com/how-to-install-snort-ids-on-windows     &#171; Time to go to college NOT &#160; [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://blog.amarkulo.com/how-to-install-snort-ids-on-windows" rel="nofollow">http://blog.amarkulo.com/how-to-install-snort-ids-on-windows</a>     &laquo; Time to go to college NOT &nbsp; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: FooSpidy &#187; Blog Archive &#187; A fairly decent honeypot</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-64</link>
		<dc:creator>FooSpidy &#187; Blog Archive &#187; A fairly decent honeypot</dc:creator>
		<pubDate>Sun, 20 Jun 2010 14:23:24 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-64</guid>
		<description>[...] Snort release the needed tweaks may vary. A good guide for installing Snort on Windows can be found here. Below are instructions for tweaking the snort.conf file as of the 2.8.6 Snort [...]</description>
		<content:encoded><![CDATA[<p>[...] Snort release the needed tweaks may vary. A good guide for installing Snort on Windows can be found here. Below are instructions for tweaking the snort.conf file as of the 2.8.6 Snort [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: steve</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-63</link>
		<dc:creator>steve</dc:creator>
		<pubDate>Thu, 01 Apr 2010 16:12:37 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-63</guid>
		<description>Well I&#039;ll try it again the lines you have are not the same using Notepad ++ 269 270 are not what you have listed nor ar the otheres i will try and see if i find them line by line thanks</description>
		<content:encoded><![CDATA[<p>Well I&#8217;ll try it again the lines you have are not the same using Notepad ++ 269 270 are not what you have listed nor ar the otheres i will try and see if i find them line by line thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amar Kulo</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-62</link>
		<dc:creator>Amar Kulo</dc:creator>
		<pubDate>Thu, 01 Apr 2010 15:56:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-62</guid>
		<description>You are getting that because you didn&#039;t read my blog post and you didn&#039;t edited snort.conf like i have wrote. You need to point snort to look on right places because default conf is for linux and that&#039;s why you need to edit it like I have described above.</description>
		<content:encoded><![CDATA[<p>You are getting that because you didn&#8217;t read my blog post and you didn&#8217;t edited snort.conf like i have wrote. You need to point snort to look on right places because default conf is for linux and that&#8217;s why you need to edit it like I have described above.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: steve</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-61</link>
		<dc:creator>steve</dc:creator>
		<pubDate>Thu, 01 Apr 2010 15:52:14 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-61</guid>
		<description>with -K i get
error: C:\Documents and setting\snort\destop\snort-2.8.5.3\src\parser.c(5050)
Could not stat dynamic module path &quot;/usr/local/lib/snort_dynamicpreprocessor/&quot;:
no such file or directory
fatal error, quitting...</description>
		<content:encoded><![CDATA[<p>with -K i get<br />
error: C:\Documents and setting\snort\destop\snort-2.8.5.3\src\parser.c(5050)<br />
Could not stat dynamic module path &#8220;/usr/local/lib/snort_dynamicpreprocessor/&#8221;:<br />
no such file or directory<br />
fatal error, quitting&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amar Kulo</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-60</link>
		<dc:creator>Amar Kulo</dc:creator>
		<pubDate>Thu, 01 Apr 2010 15:29:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-60</guid>
		<description>You need to pay attention to case of the switch, because -k and -K are not the same.

-k &lt;mode&gt;  Checksum mode (all,noip,notcp,noudp,noicmp,none)
-K &lt;mode&gt;  Logging mode (pcap[default],ascii,none)</description>
		<content:encoded><![CDATA[<p>You need to pay attention to case of the switch, because -k and -K are not the same.</p>
<p>-k <mode>  Checksum mode (all,noip,notcp,noudp,noicmp,none)<br />
-K </mode><mode>  Logging mode (pcap[default],ascii,none)</mode></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: steve</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-59</link>
		<dc:creator>steve</dc:creator>
		<pubDate>Thu, 01 Apr 2010 15:27:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-59</guid>
		<description>Got a fatal error when i took out -k ascii but when i add just the -k it seems to runs fine shows me a lot of information including what looks like all the commands might it be working correctly now?</description>
		<content:encoded><![CDATA[<p>Got a fatal error when i took out -k ascii but when i add just the -k it seems to runs fine shows me a lot of information including what looks like all the commands might it be working correctly now?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amar Kulo</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-58</link>
		<dc:creator>Amar Kulo</dc:creator>
		<pubDate>Thu, 01 Apr 2010 15:11:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-58</guid>
		<description>Hmm strange, try without -K ascii switch</description>
		<content:encoded><![CDATA[<p>Hmm strange, try without -K ascii switch</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: steve</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-57</link>
		<dc:creator>steve</dc:creator>
		<pubDate>Thu, 01 Apr 2010 15:10:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-57</guid>
		<description>I get a Unknown command line checksum option: ascii fatal error, quiting
when i do that</description>
		<content:encoded><![CDATA[<p>I get a Unknown command line checksum option: ascii fatal error, quiting<br />
when i do that</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amar Kulo</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-56</link>
		<dc:creator>Amar Kulo</dc:creator>
		<pubDate>Thu, 01 Apr 2010 15:00:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-56</guid>
		<description>Nope, I&#039;m referring to the post above comments. There I have written snort -v -c C:\snort\etc\snort.conf -l C:\snort\log -K ascii  as a line to test everything from command prompt ;-)

I&#039;m glad that I could help.</description>
		<content:encoded><![CDATA[<p>Nope, I&#8217;m referring to the post above comments. There I have written snort -v -c C:\snort\etc\snort.conf -l C:\snort\log -K ascii  as a line to test everything from command prompt <img src='http://blog.amarkulo.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>I&#8217;m glad that I could help.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: steve</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-55</link>
		<dc:creator>steve</dc:creator>
		<pubDate>Thu, 01 Apr 2010 14:56:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-55</guid>
		<description>Not sure i follow you is the blog post on twitter ? sorry new to this side of IT im just build kiosks for stores and just started school to get some more knowledge but Seems like i have a ways to go</description>
		<content:encoded><![CDATA[<p>Not sure i follow you is the blog post on twitter ? sorry new to this side of IT im just build kiosks for stores and just started school to get some more knowledge but Seems like i have a ways to go</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amar Kulo</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-54</link>
		<dc:creator>Amar Kulo</dc:creator>
		<pubDate>Thu, 01 Apr 2010 14:26:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-54</guid>
		<description>The easiest way to run snort for testing is to run command prompt and from there to write all commands. You can read blog post again and see how did I do it from command prompt for testing. When you edit snort.conf file you just need to pass it to snort.exe with -c path_to_config_file and some extra parameters for testing like verbose, interface number if needed and so on.

I have wrote about that in blog post.</description>
		<content:encoded><![CDATA[<p>The easiest way to run snort for testing is to run command prompt and from there to write all commands. You can read blog post again and see how did I do it from command prompt for testing. When you edit snort.conf file you just need to pass it to snort.exe with -c path_to_config_file and some extra parameters for testing like verbose, interface number if needed and so on.</p>
<p>I have wrote about that in blog post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: steve</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-53</link>
		<dc:creator>steve</dc:creator>
		<pubDate>Thu, 01 Apr 2010 14:22:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-53</guid>
		<description>Ok seems when  run that command now i get the list of commands and and the final line says you need to tell me to do something.Thank you so much im in the process of trying to find these commands in the .conf they seem to be in different places then you have it on here im using the Notepad++.</description>
		<content:encoded><![CDATA[<p>Ok seems when  run that command now i get the list of commands and and the final line says you need to tell me to do something.Thank you so much im in the process of trying to find these commands in the .conf they seem to be in different places then you have it on here im using the Notepad++.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amar Kulo</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-52</link>
		<dc:creator>Amar Kulo</dc:creator>
		<pubDate>Thu, 01 Apr 2010 13:08:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-52</guid>
		<description>Snort is not recognized as a command because you don&#039;t have it in path but that&#039;s ok, you just need to enter c:\snort\bin and run snort from there or type whole path c:\snort\bin\snort.exe

Regarding the second problem, .conf file is a text file, you can edit it notepad, wordpad or any other text editor, I prefer notepad++ which is free and works really good.</description>
		<content:encoded><![CDATA[<p>Snort is not recognized as a command because you don&#8217;t have it in path but that&#8217;s ok, you just need to enter c:\snort\bin and run snort from there or type whole path c:\snort\bin\snort.exe</p>
<p>Regarding the second problem, .conf file is a text file, you can edit it notepad, wordpad or any other text editor, I prefer notepad++ which is free and works really good.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: steve</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-51</link>
		<dc:creator>steve</dc:creator>
		<pubDate>Thu, 01 Apr 2010 13:03:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-51</guid>
		<description>I get snort is not recognized command through that command prompt. So i went back and saw i need to configure this to be active but when i go to the C:\Snort\etc\snort.conf  file it seems i dont have a program installed that will read it. When i right click it doesnt give me the Open With option so how would i configure it ? Other then winpcap is there something else i  would need? Snort.com mentions Barnyard but this is also in a format the is unreadable in my Virtual.</description>
		<content:encoded><![CDATA[<p>I get snort is not recognized command through that command prompt. So i went back and saw i need to configure this to be active but when i go to the C:\Snort\etc\snort.conf  file it seems i dont have a program installed that will read it. When i right click it doesnt give me the Open With option so how would i configure it ? Other then winpcap is there something else i  would need? Snort.com mentions Barnyard but this is also in a format the is unreadable in my Virtual.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amar Kulo</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-50</link>
		<dc:creator>Amar Kulo</dc:creator>
		<pubDate>Thu, 01 Apr 2010 12:41:31 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-50</guid>
		<description>Strange because I have done this on vmware with 2003 as guest and xp as host and it worked without any problems. How do you start snort? Which error messages are you receiving?</description>
		<content:encoded><![CDATA[<p>Strange because I have done this on vmware with 2003 as guest and xp as host and it worked without any problems. How do you start snort? Which error messages are you receiving?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: steve</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-49</link>
		<dc:creator>steve</dc:creator>
		<pubDate>Thu, 01 Apr 2010 12:38:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-49</guid>
		<description>Been trying to install snort on a virtual machine. The virtual is through VMware and its Windows 2003 server. And the actuall physical computer is Windows 7 I cannot get this to work i have Winpcap and have installed it and i have the rules and have installed them. All the files within my Snort folder are not able to be read by my Virtual machine 2003 server. Is there something i didnt download i have all the files snort.com says you need and none of those can be read either. What did i miss?</description>
		<content:encoded><![CDATA[<p>Been trying to install snort on a virtual machine. The virtual is through VMware and its Windows 2003 server. And the actuall physical computer is Windows 7 I cannot get this to work i have Winpcap and have installed it and i have the rules and have installed them. All the files within my Snort folder are not able to be read by my Virtual machine 2003 server. Is there something i didnt download i have all the files snort.com says you need and none of those can be read either. What did i miss?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amar Kulo</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-48</link>
		<dc:creator>Amar Kulo</dc:creator>
		<pubDate>Mon, 15 Feb 2010 07:49:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-48</guid>
		<description>Sorry, it was my mistake that one extra &quot;\&quot; was left behind on preprocesor line. Now it&#039;s removed.

Regardin logs, if you are using -l path then check if snort can write to log directory.

Instruction says that  &lt;em&gt;config detection: search-method ac-bnfa max_queue_events 5&lt;/em&gt; should be written on one line, not on two, and if you are writing them on 2 then you need &quot;\&quot; on the end of the first line.</description>
		<content:encoded><![CDATA[<p>Sorry, it was my mistake that one extra &#8220;\&#8221; was left behind on preprocesor line. Now it&#8217;s removed.</p>
<p>Regardin logs, if you are using -l path then check if snort can write to log directory.</p>
<p>Instruction says that  <em>config detection: search-method ac-bnfa max_queue_events 5</em> should be written on one line, not on two, and if you are writing them on 2 then you need &#8220;\&#8221; on the end of the first line.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gregg</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-47</link>
		<dc:creator>gregg</dc:creator>
		<pubDate>Mon, 15 Feb 2010 01:22:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-47</guid>
		<description>Regarding  ennguyennguyen&#039;s problem with max_queue_events:

The instructions say to use this:
  config detection: search-method ac-bnfa
  max_queue_events 5

But this is missing a &quot;\&quot; after &quot;ac-bnfa&quot; to ensure this is interpreted as one long command without an end-of-line.  Alternatively, you can simply write it as
  config detection: search-method ac-bnfa max_queue_events 5

As for problems incurred by an extra trailing &quot;\&quot;, make sure there is nothing on the line that follows, so that the command interpreter will pick up the end-of-line.  &quot;\&quot; is just for readability.  If your code is all mashed up so that one command follows another without a blank line, and you are using trailing &quot;\&quot;, then the interpreter won&#039;t know where parameters end and the next command begins.  For example, the code segment:

  preprocessor ftp_telnet_protocol: \
  preprocessor ftp_telnet_protocol: \

will try to be read as
  preprocessor ftp_telnet_protocol: preprocessor ftp_telnet_protocol:

which is nonsense.

Make sure you have newlines where newlines are needed, and &quot;\&quot; where the command is NOT supposed to end.</description>
		<content:encoded><![CDATA[<p>Regarding  ennguyennguyen&#8217;s problem with max_queue_events:</p>
<p>The instructions say to use this:<br />
  config detection: search-method ac-bnfa<br />
  max_queue_events 5</p>
<p>But this is missing a &#8220;\&#8221; after &#8220;ac-bnfa&#8221; to ensure this is interpreted as one long command without an end-of-line.  Alternatively, you can simply write it as<br />
  config detection: search-method ac-bnfa max_queue_events 5</p>
<p>As for problems incurred by an extra trailing &#8220;\&#8221;, make sure there is nothing on the line that follows, so that the command interpreter will pick up the end-of-line.  &#8220;\&#8221; is just for readability.  If your code is all mashed up so that one command follows another without a blank line, and you are using trailing &#8220;\&#8221;, then the interpreter won&#8217;t know where parameters end and the next command begins.  For example, the code segment:</p>
<p>  preprocessor ftp_telnet_protocol: \<br />
  preprocessor ftp_telnet_protocol: \</p>
<p>will try to be read as<br />
  preprocessor ftp_telnet_protocol: preprocessor ftp_telnet_protocol:</p>
<p>which is nonsense.</p>
<p>Make sure you have newlines where newlines are needed, and &#8220;\&#8221; where the command is NOT supposed to end.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ennguyennguyen</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-46</link>
		<dc:creator>ennguyennguyen</dc:creator>
		<pubDate>Wed, 13 Jan 2010 19:00:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-46</guid>
		<description>Amar Kulo, why can&#039;t my snort write log file into folders? I try many ways, but that still doesn&#039;t work.</description>
		<content:encoded><![CDATA[<p>Amar Kulo, why can&#8217;t my snort write log file into folders? I try many ways, but that still doesn&#8217;t work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ennguyennguyen</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-45</link>
		<dc:creator>ennguyennguyen</dc:creator>
		<pubDate>Wed, 13 Jan 2010 13:11:37 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-45</guid>
		<description>Yes, I&#039;m waiting for you. Actually, I decided to ignore IDSCenter. Instead of IDSCenter, I run snort through command line.

BUT still I have trouble with snort. I try apacheDoS and guess what, Snort doesn&#039;t write any log into alert.ids. But when I using nmap, Snort writes log. What wrong with that? Can you suggest me some more tools to test Snort?

Thank you so much.</description>
		<content:encoded><![CDATA[<p>Yes, I&#8217;m waiting for you. Actually, I decided to ignore IDSCenter. Instead of IDSCenter, I run snort through command line.</p>
<p>BUT still I have trouble with snort. I try apacheDoS and guess what, Snort doesn&#8217;t write any log into alert.ids. But when I using nmap, Snort writes log. What wrong with that? Can you suggest me some more tools to test Snort?</p>
<p>Thank you so much.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amar Kulo</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-44</link>
		<dc:creator>Amar Kulo</dc:creator>
		<pubDate>Wed, 13 Jan 2010 10:10:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-44</guid>
		<description>Hmm I have tested my conf and still don&#039;t have problem with trailing \. I have updated post with my snort.conf file just for the records.

Regarding stream5 preprocessor, I don&#039;t know why is it complaining because stream5 should be in dynamic engine, there is no separate preprocessor .dll file for it.

Test with my config file and see what happens.

I don&#039;t use IDSCenter, but I will give it a go to see what kind of problems are you having.</description>
		<content:encoded><![CDATA[<p>Hmm I have tested my conf and still don&#8217;t have problem with trailing \. I have updated post with my snort.conf file just for the records.</p>
<p>Regarding stream5 preprocessor, I don&#8217;t know why is it complaining because stream5 should be in dynamic engine, there is no separate preprocessor .dll file for it.</p>
<p>Test with my config file and see what happens.</p>
<p>I don&#8217;t use IDSCenter, but I will give it a go to see what kind of problems are you having.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ennguyennguyen</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-43</link>
		<dc:creator>ennguyennguyen</dc:creator>
		<pubDate>Tue, 12 Jan 2010 10:49:38 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-43</guid>
		<description>Snort really is a big mess. When I can run snort in command line, I failed to start Snort in IDSCenter. IDSCenter refrase the snort.conf in somekind of structure and it cause Snort failed to start. Can you post an entry show us how to configure IDSCenter? I&#039;m going crazy with this.

Exactly, I have problems with the preprocessor bo.

preprocessor bo

preprocessor frag3_global: max_frags 65536
preprocessor frag3_engine: policy windows timeout 180
preprocessor stream5_global: max_tcp 8192, track_tcp yes, track_udp yes
preprocessor stream5_tcp: policy windows, use_static_footprint_sizes,
preprocessor stream5_udp: ignore_any_rules
preprocessor http_inspect: global iis_unicode_map unicode.map 1252
preprocessor http_inspect_server: default_server
preprocessor ftp_telnet: \
preprocessor ftp_telnet_protocol: \
preprocessor ftp_telnet_protocol: \
preprocessor ftp_telnet_protocol: \
preprocessor SMTP: \
preprocessor ssh: server_ports { 22 } \
preprocessor ssl: ports { 443 465 563 636 989 992 993 994 995 7801 7702 7900 7901
7902 7903 7904 7905 7906 6907 7908 7909 7910 7911 7912 7913 7914 7915 7916 7917
7918 7919 7920 }, trustservers, noinspect_encrypted
preprocessor dcerpc2: memcap 102400, events [co ]
preprocessor dcerpc2_server: default, policy WinXP, \
preprocessor dns: ports { 53 } enable_rdata_overflow

This mess, from stream5 to the end of this. I always have trouble like &quot;unknown preprocessor stream5&quot; or &quot;must configure http inspect global configuration first&quot; and so far, ftp_telnet, bla bla bla....

Thanks!!!!</description>
		<content:encoded><![CDATA[<p>Snort really is a big mess. When I can run snort in command line, I failed to start Snort in IDSCenter. IDSCenter refrase the snort.conf in somekind of structure and it cause Snort failed to start. Can you post an entry show us how to configure IDSCenter? I&#8217;m going crazy with this.</p>
<p>Exactly, I have problems with the preprocessor bo.</p>
<p>preprocessor bo</p>
<p>preprocessor frag3_global: max_frags 65536<br />
preprocessor frag3_engine: policy windows timeout 180<br />
preprocessor stream5_global: max_tcp 8192, track_tcp yes, track_udp yes<br />
preprocessor stream5_tcp: policy windows, use_static_footprint_sizes,<br />
preprocessor stream5_udp: ignore_any_rules<br />
preprocessor http_inspect: global iis_unicode_map unicode.map 1252<br />
preprocessor http_inspect_server: default_server<br />
preprocessor ftp_telnet: \<br />
preprocessor ftp_telnet_protocol: \<br />
preprocessor ftp_telnet_protocol: \<br />
preprocessor ftp_telnet_protocol: \<br />
preprocessor SMTP: \<br />
preprocessor ssh: server_ports { 22 } \<br />
preprocessor ssl: ports { 443 465 563 636 989 992 993 994 995 7801 7702 7900 7901<br />
7902 7903 7904 7905 7906 6907 7908 7909 7910 7911 7912 7913 7914 7915 7916 7917<br />
7918 7919 7920 }, trustservers, noinspect_encrypted<br />
preprocessor dcerpc2: memcap 102400, events [co ]<br />
preprocessor dcerpc2_server: default, policy WinXP, \<br />
preprocessor dns: ports { 53 } enable_rdata_overflow</p>
<p>This mess, from stream5 to the end of this. I always have trouble like &#8220;unknown preprocessor stream5&#8243; or &#8220;must configure http inspect global configuration first&#8221; and so far, ftp_telnet, bla bla bla&#8230;.</p>
<p>Thanks!!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ennguyennguyen</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-42</link>
		<dc:creator>ennguyennguyen</dc:creator>
		<pubDate>Tue, 12 Jan 2010 10:13:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-42</guid>
		<description>I follow your step, ignore the last &quot;/&quot;. Snort run smoothly, but there still an error:

ERROR: c:\snort\etc\snort.conf(273) Unknown rule type: max_queue_events.

I wonder what this problem is.</description>
		<content:encoded><![CDATA[<p>I follow your step, ignore the last &#8220;/&#8221;. Snort run smoothly, but there still an error:</p>
<p>ERROR: c:\snort\etc\snort.conf(273) Unknown rule type: max_queue_events.</p>
<p>I wonder what this problem is.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amar Kulo</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-41</link>
		<dc:creator>Amar Kulo</dc:creator>
		<pubDate>Fri, 08 Jan 2010 19:41:37 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-41</guid>
		<description>It could be, I will test it on Monday and fix it in post if it is correct.

Tnx for the tip anyway. :-)</description>
		<content:encoded><![CDATA[<p>It could be, I will test it on Monday and fix it in post if it is correct.</p>
<p>Tnx for the tip anyway. <img src='http://blog.amarkulo.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>

