blob: b9cc18b8a51a038065dfdb3b02c5af03127c5cb7 (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
|
***********************************
* !!!!!!!!!!! WARNING !!!!!!!!!!! *
***********************************
A startup script was installed in %%PREFIX%%/etc/rc.d/. Enable the script
in /etc/rc.conf using the usual rc.subr syntax. See rc.conf(5) or go to
http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/configtuning-rcng.html
Configuration files named sancp.conf-dist and sancp.conf
were installed in %%PREFIX%%/etc. See the INSTALL doc, located in
%%PREFIX%%/share/doc/sancp/ for details on configuration
options or type "sancp -h" on the commandline.
Note that if you are installing sancp for use with sguil, the
sancp.conf file will not be altered unless it is identical to
the sancp.conf-dist file. In that case, during the
sguil-sensor install, the sancp.conf file will be overwritten with
the one that comes with squil. That file needs no editing. If the
sancp.conf has been altered (you used sancp for something else) a
new conf file, named sguil-sancp.conf-sample will be installed in the
%%PREFIX%%/etc directory. You should use that one for sguil.
Some of the configuration options for sancp are:
-? or -h this help screen
-c <filename> specify the configuration/rules filename
-d <directory> specify the directory for output files
-i <device> set the network device to listen on (default: 'any')
-g <gid> set a group identity
-u <uid> set a user identity
-D (daemon) forks, prints msgs to syslog only and overrides -C option
-F <bpf filename> file containing a bpf filter expression, overrides (alternative to -B)
-V display version
If you're running sguil, you probably want to use the following flags:
sancp_flags="-D -P -R -u sancp -g sancp -d /var/log/sancp"
(don't forget to specify the conf file and interface as well)
|