Snort mailing list archives

Initial snort.conf


From: vishesh kumar <linuxtovishesh () gmail com>
Date: Thu, 27 Jan 2011 21:25:32 +0530

I am newbie in snort. I written following lines in snort.conf
 ipvar HOME_NET 192.168.1.0
 ipvar EXTERNAL_NET any
 preprocessor stream5_global : max_tcp 8192, track_tcp yes, track_udp
no,track_icmp no
 preprocessor stream5_tcp : detect_anomalies

Then i started snort with following command
 root#snort -c snort.conf -l /var/log/snort -A fast

But problem is that nothing is getting logged in /var/log/snort/alert,
even though i am sending forged SYN request using scapy. I tried
multiple invlaid TCP sessions but nothing get logged .
What may be the error?

Thanks

-- 
http://linuxmantra.com

------------------------------------------------------------------------------
Special Offer-- Download ArcSight Logger for FREE (a $49 USD value)!
Finally, a world-class log management solution at an even better price-free!
Download using promo code Free_Logger_4_Dev2Dev. Offer expires 
February 28th, so secure your free ArcSight Logger TODAY! 
http://p.sf.net/sfu/arcsight-sfd2d
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: