Snort mailing list archives

Basic snort setup for traffic analysis


From: "Nanabhay Mohamed * Group (GP)" <MohamedN () Transnet co za>
Date: Mon, 30 Sep 2002 12:34:59 +0200

Hi,
 
I want to run snort on a network for about 5 days and then use snortsnarf
(or anything else someone can recommend) to analyse what sort of traffic is
going through the network. 
 
Firstly, can anyone advise me on what sort of options (parameters) I should
run snort with in this exercise and also what rulesets I can leave out?
 
Secondly, I intend to place snort behind and infront of the firewall. Are
there any tools that do comparative analysis?
 
Thanks in advance,
 
Mohamed 
 
Information Systems Security Services (IS3)
Transnet Group Audit Services
 

Current thread: