Snort mailing list archives
Tweaking false positives
From: "kaidhai" <kaidhai () yahoo com>
Date: Fri, 21 Sep 2001 22:25:35 +0530
Dear all, I am receiving a large number of alerts from a specific machine (DNS) that exists in my own LAN and is trusted. I want the alerts for such machines (ie, all such false positives) to be reduced. Any answers to that? Thanks in advance. Regards
Current thread:
- Tweaking false positives kaidhai (Sep 21)
- Re: Tweaking false positives Erek Adams (Sep 21)