In config file snort.conf need set up
config daq: pcap
config daq_dir: /usr/lib/daq —because this is set only in init file so when runing snort via cmd ends error without this
These alerts, oddly, are not available for viewing with a simple “cat /var/log/messages” and nor are they showing up in my graylog2 instance. I only found them with: cat /var/log/messages |grep snort
A note - I also updated the snort rules using pulledpork.pl on a different host and synced them over to the turris box. I also disabled DNP and MOD processors to reduce memory consumption.