I have installed Snort 2.9.05 using Artica. On Artica, it shows Snort is running. However, when I checked snort.conf, it listed
var HOME_NET 188.165.241.0/24 which is not my network. My network is 192.168.2.0/24. When I changed /etc/snort/snort.conf, it always revert to 188.165.241.0/24. Where do I need to change to fix this problem.
If I run /etc/init.d/snort start, it return with error: /etc/snort/snort.conf: 1: var: not found
How can I be sure that Snort is running?
Thanks,
Kim
