Snort mailing list archives

Rules not working?


From: "Erik Tank" <erik () jundy com>
Date: Thu, 5 Jun 2003 01:25:30 -0700

Long story about what I'm trying to do so I'll skip it.  Here's the problem:

I am launching an attach from one of my IPs to another one - so I know that there is traffic out there.
I Snort - using the rules - for 50,000 packets and my alert log barely has 70 entries in it.
I Snort - from the command line using no rules - for 10 seconds and then check the output log for the IP that I am 
launching the attach from and I see 18,205 UDP packets.

I would assume that SNORT should pick up the UDP flood, but for some reason the rules aren't picking them up.  I am 
using the rules that are provided at http://www.snort.org/dl/rules/ from a month ago.

Any help or suggestions would be greatly appreciated,

Erik Tank

Current thread: