Snort mailing list archives
Snort Rule Question
From: "Nick Patellis" <NPatellis () TheFund com>
Date: Mon, 17 Feb 2003 16:00:50 -0500
I am trying to stop an alert on specific rules against specific http servers. How is this done? Assume the alert starts with: alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS..... if http_servers = home_network, how do I stop this from alerting on certain servers? Can I use a list of ip addresses for the HTTP_SERVERS variable? Thanks
Current thread:
- Snort Rule Question Nick Patellis (Feb 17)
- Re: Snort Rule Question Erick Mechler (Feb 17)