Snort mailing list archives
suggestion?
From: "Slighter, Tim" <tslighter () itc nrcs usda gov>
Date: Wed, 15 Jan 2003 08:38:13 -0700
If what I am about to say is already present and available then please disregard this post. Otherwise, what are the possibilities for implementing event propagation features into snort. Say for example when snort alerts for a SubSeven Scan and as everyone knows, this can generate thousands of alerts. Is it possible to build into the code or the conf/rules files an option that would instruct snort to stop logging for this alert based upon the source address and after "x" number of similar alerts for "x" amount of time?
Current thread:
- suggestion? Slighter, Tim (Jan 15)
- <Possible follow-ups>
- RE: suggestion? Steve Halligan (Jan 15)