The default /etc/snort/snort.conf seems to contain a lot of stuff that causes the daemon not to start up.. snort[7565]: FATAL ERROR: /etc/snort/snort.conf(182) => Unknown rule type: dynamicpreprocessor Is there some module missing perhaps? Or a missing dependancy on the snort rpm?
Dave the dynamic preprocessor is new and i have yet to have it in the rpm. Its high on my list of priorities. alot of the other missing items we can not redistribute due to the license that they are released under. unfortunately as shipped there is no way to make the default config just work and do something useful.
Might be worth looking to see what the Debian folks did. When I last setup a snort box I pretty much only had to set up the IP to listen on, and it 'just worked'. I'll dupe this against the earlier snort bug that seems to be the same thing. *** This bug has been marked as a duplicate of 196046 ***