IDS mailing list archives

Re: Intrushield


From: "Chris Brown" <chris () get-tuf com>
Date: Sun, 23 Jan 2005 19:49:07 -0000 (GMT)

To view the captured packets ensure you change the check box in the alert
viewer to correspond to the level of logging that you specified when
modifying the rule.  Have you installed Ethereal and pointed the
Intrushield manager to the executable?

It all works fine for me and I have had no trouble viewing alert packets
or entire flows (useful for checking possible false positives).

"I have yet to get the logging capability to work. You can set it to log X
packets, but it won't display them when you view alerts."



I could fly like an Eagle but Weasels don’t get sucked into jet engines.



--------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from 
CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
to learn more.
--------------------------------------------------------------------------


Current thread: