Swatch doesn't work on snort script
Brought to you by:
toddatkins
Afetr version up to latest snort-2.3.2, swatch does not start and indicate
alert as follows.
Substitution replacement not terminated at /root/.swatch_script.**** line
201.
**** is a script number and changed everytime when to start swatch.
Please teach me, how to resolve this problem.
Logged In: NO
additiona information!
swatch version 3.1.1
other log can be taken by swatch, for example /var/log/messages and /var/log/
secure. Just not can not be taken snort alert.
snort openning script as follows
swatch -c /etc/swatchrc/.swatchrc_snort_alert -t /var/log/snort/alert
snort version up on source, not rpm.