Dependencies on Ubuntu 8.04n:
apt-get install libpcap0.8-dev libpcre3-dev flex bison install http://code.google.com/p/libdnet/ install DAQ: http://www.snort.org/downloads/801
Dependencies on Ubuntu 10.04:
apt-get install libpcap0.8-dev libpcre3-dev flex bison zlib1g-dev install http://code.google.com/p/libdnet/ install DAQ: http://www.snort.org/downloads/801
Configure snort with –enable-zlib
Name Type Extraction/Transform Owner App Sharing Status Actions syslog : EXTRACT-dip Inline \d+\.\d+\.\d+\.\d+(?:\:\d+)* -> (?<dip>\d+\.\d+\.\d+\.\d+)(?:\:\d+)*\s*$ syslog : EXTRACT-dport Inline -> \d+\.\d+\.\d+\.\d+\:(?<dport>\d+)\s*$ syslog : EXTRACT-gid Inline \[(?<gid>\d+)\:\d+\:\d+\] syslog : EXTRACT-sid Inline \[\d+\:(?<sid>\d+)\:\d+\] syslog : EXTRACT-signame Inline \[\d+\:\d+\:\d+\]\s*(?<signame>.+?)\s*\[Classification syslog : EXTRACT-sip Inline (?<sip>\d+\.\d+\.\d+\.\d+)(?:\:\d+)* -> \d+\.\d+\.\d+\.\d+(?:\:\d+)*\s*$ syslog : EXTRACT-sport Inline \d+\.\d+\.\d+\.\d+\:(?<sport>\d+) ->