Snort mailing list archives

Snort Rule Question


From: "Nick Patellis" <NPatellis () TheFund com>
Date: Mon, 17 Feb 2003 16:00:50 -0500

I am trying to stop an alert on specific rules against specific http
servers.  How is this done?  Assume the alert starts with:  alert tcp
$EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS.....  if http_servers =
home_network, how do I stop this from alerting on certain servers?  Can
I use a list of ip addresses for the HTTP_SERVERS variable?

 

Thanks 

 


Current thread: