Open your linux terminal
sudo add-apt-repository universe
sudo apt update
sudo apt install -y gcc libpcre3-dev zlib1g-dev libluajit-5.1-dev libpcap-dev openssl libssl-dev libnghttp2-dev libdumbnet-dev bison flex libdnet
sudo apt-get install snort
Check you have it installed.
you’ll be asked to accept an interface, do so and then
sudo snort -c /etc/snort/snort.conf -l /var/log/snort/ -A full
Your snort is running..
-c tells us snort where the configuration file is located.
-l tells snort where the log file is created.
-A refers to the Alert, if we write “full” we tell snort to log all packets.