![snort logo](/images/snort-logo.png)
Snort mailing list archives
Rules not working?
From: "Erik Tank" <erik () jundy com>
Date: Thu, 5 Jun 2003 01:25:30 -0700
Long story about what I'm trying to do so I'll skip it. Here's the problem: I am launching an attach from one of my IPs to another one - so I know that there is traffic out there. I Snort - using the rules - for 50,000 packets and my alert log barely has 70 entries in it. I Snort - from the command line using no rules - for 10 seconds and then check the output log for the IP that I am launching the attach from and I see 18,205 UDP packets. I would assume that SNORT should pick up the UDP flood, but for some reason the rules aren't picking them up. I am using the rules that are provided at http://www.snort.org/dl/rules/ from a month ago. Any help or suggestions would be greatly appreciated, Erik Tank
Current thread:
- Rules not working? Erik Tank (Jun 05)
- Re: Rules not working? Joerg Weber (Jun 05)
- Re: Rules not working? Matt Kettler (Jun 05)