Snort mailing list archives

Tweaking false positives


From: "kaidhai" <kaidhai () yahoo com>
Date: Fri, 21 Sep 2001 22:25:35 +0530

Dear all,
I am receiving a large number of alerts from a specific machine (DNS) that exists in my own LAN and is trusted.  I want 
the alerts for such machines (ie, all such false positives) to be reduced.  Any answers to that? Thanks in advance.
Regards

Current thread: