sniffer --> preprocessor --> detection engine --> alert/logging
$ snort -V
$ snort -T -c /etc/snort/snort.conf
$ cd /etc/snort/rules $ ls
$ vi /etc/snort/snort.conf
$ ls /var/log/snort