This is a discussion on Re: [Snort-users] Any way to change permissions of the unified output files? within the Snort forums, part of the System Security and Security Related category; From ./snort --help -m <umask> Set umask =3D <umask> Bammkkkk On 5/25/05, Rob Baxter &...
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
From ./snort --help
-m <umask> Set umask =3D <umask> Bammkkkk On 5/25/05, Rob Baxter <rbaxter@xapiens.net> wrote: >=20 > The output files generated by the unified output plugin (ie the alert > and log files) always seem to be created with only rw permissions for > the root user. I need to collect the log files from a Solaris machine > which does not allow remote root logins. Is there any way to get snort > to set a different acl on the output files? I've tried using the -u > option to run snort as a different user but the files still get created > as root. I can whip up a cron job to periodically chown the files but > I'd prefer something less hackey. >=20 > </rob> >=20 >=20 --=20 sguil - The Analyst Console for NSM http://sguil.sf.net ------------------------------------------------------- SF.Net email is sponsored by: GoToMeeting - the easiest way to collaborate online with coworkers and clients while avoiding the high cost of travel and communications. There is no equipment to buy and you can meet as often as you want. Try it free.http://ads.osdn.com/?ad_id=7402&alloc_id=16135&op=click _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/...fo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.p...st=snort-users |
![]() |
| Thread Tools | |
| Display Modes | |
|
|