Need help - pads not working on RHEL 6 64-bit server
Hi All,
I hope to get some help with pads issue I'm running into. I can't get it work on RHEL 6 64-bit server. I got Sguil 8 working, all except pads on sensor.
Download source pads-1.2-sguil-mods.tar.gz from:
http://demo.sguil.net/downloads/ (This website is not opening, I had a copy downloaded from the same website back in 2008, so I'm using that copy).
Patch and compile:
patch -p0 < ./pads.patch
./configure --prefix=/usr/local/pads-1.2-squil-mods
make
make install
Create symbolic links:
ln -s /usr/local/pads-1.2-squil-mods
/usr/local/pads
ln -s
/usr/local/pads/bin/pads /usr/local/bin/
Create /etc/sguil/pads.conf as following:
daemon 1
pid_file /var/run/sguil/pads.pid
interface eth1
output fifo: /nsm/snort_data/mysensor/pads.fifo
Run pads:
/usr/local/bin/pads -c /etc/sguil/pads.conf -u sguil -g sguil
Here's the error info in /var/log/messages (tried twice):
Jan 22 10:49:50 SENSOR pads: WARNING: pcap_lookupnet (eth1: no IPv4 address
assigned)
Jan 22 10:49:50 SENSOR pads: Filter: (null)
Jan 22 10:49:50 SENSOR pads: Listening on
interface eth1
Jan 22 10:49:50 SENSOR kernel: pads[7701]:
segfault at 85356d8 ip 00000000004044be sp 00007fff216fc248 error 4 in
pads[400000+d000]
Jan 22 11:09:18 SENSOR pads: WARNING: pcap_lookupnet (eth1: no IPv4 address
assigned)
Jan 22 11:09:18 SENSOR pads: Filter: (null)
Jan 22 11:09:18 SENSOR pads: Listening on
interface eth1
Jan 22 11:09:18 SENSOR kernel: pads[7773]:
segfault at cb3226d8 ip 0000003c8ec47a67 sp 00007fff715c9680 error 4 in
libc-2.12.so[3c8ec00000+186000]
I have re-compiled again, but still getting segfault error. Any suggestions?
Thanks.
Jamie
------------------------------------------------------------------------------
Try before you buy = See our experts in action!
The most comprehensive online learning library for Microsoft developers
is just $99.99! Visual Studio, SharePoint, SQL - plus HTML5, CSS3, MVC3,
Metro Style Apps, more. Free future releases when you subscribe now!
http://p.sf.net/sfu/learndevnow-dev2
_______________________________________________
Sguil-users mailing list
Sguil-users@...
https://lists.sourceforge.net/lists/listinfo/sguil-users