Installing Snort on Linux :
First download Snort’s latest version “snort-2.9.1.2.tar.gz” using the following command :
wget http://www.snort.org/dl/snort-current/snort-2.9.1.2.tar.gz -O snort-2.9.1.2.tar.gz
Run the following commands to proceed with installation:
tar zxf snort-2.9.1.2.tar.gz
cd snort-2.9.1.2
./configure
make
make install
While installing Snort you may get following error:
ERROR! Libpcap library/headers (libpcap.a (or .so)/pcap.h) not found
To fix the above error you need to install the following libpcap, libpcap-devel modules:
yum install libpcap libpcap-devel
Once the above modules are installed, please re-run the snort installation process.
It will successfully Install Snort in Server.
Once the installation is complete, you need to copy the configuration files <snort-2.9.1.2>/etc/snort.conf to /etc/snort/snort.conf in your server. Alter the configuration as per your requirements.
The default rules for Snort can be found here . You can download the rules and add them to the /etc/snort/rules folder in server.