gen-msg.map missing in Snort rules?

Posted by TheLQ on Server Fault See other posts from Server Fault or by TheLQ
Published on 2011-01-29T05:02:02Z Indexed on 2011/01/29 7:28 UTC
Read the original article Hit count: 922

Filed under:

I am trying to install Snort 2.8.4.1 (only package available in the repos) with Barnyard2 with limited success. I've managed to fix everything but this:

[lordquackstar@quackwall rules]$ sudo barnyard2 -c /etc/snort/barnyard2.conf -d /var/log/snort -f snort.u2 -w /etc/snort/barny               Password:
Running in Continuous mode

        --== Initializing Barnyard2 ==--
Initializing Input Plugins!
Initializing Output Plugins!
Parsing config file "/etc/snort/barnyard2.conf"
ERROR: Unable to open Generator file "/etc/snort/gen-msg.map": No such file or directory
ERROR: Stat check on log dir (/var/log/barnyard2) failed: No such file or directory.
Fatal Error, Quitting..

The gen-msg.map error is puzzling me. The rulesets that come with the package do not contain this file. The newish rules I just downloaded from Snort.org for version 2.8.6.1 don't have this file. The only file that looks close is called sid-msg.map, but that's the wrong one.

Where can I obtain this file?

Just in case it matters: The packages come from the ClearOS repositories (OS is based off of CentOS). I'm running CentOS 5.2

© Server Fault or respective owner

Related posts about snort