Snort mailing list archives
Re: UDP and ICMP logs not linked?
From: James Hoagland <hoagland () SiliconDefense com>
Date: Wed, 6 Feb 2002 10:53:41 -0800
At 11:32 PM -0800 2/5/02, David Bellizzi wrote:
TCP alerts have links to the snort packet logs in the report but UDP and ICMP alerts do not. Did I miss something?I use the following command to generate the report. /usr/local/bin/snortsnarf.pl -dns \-d /export/htdocs/reports/snort/snortsnarf/current \-ldir /var/log/snort \ -homenet X.X.X.X/30 \ -rulesdir /usr/local/etc \ -rulesfile /usr/local/etc/snort.conf \ -refresh=60 \ /var/log/messages
David,What version of SnortSnarf are you using? And can I see a couple examples of the alerts that don't have links (you can change the IP's mentioned for posting).
-- Jim P.s. Also check out the SnortSnarf-users list. -- |* Jim Hoagland, Associate Researcher, Silicon Defense *| |* --- Silicon Defense: IDS Solutions --- *| |* hoagland () SiliconDefense com, http://www.silicondefense.com/ *| |* Voice: (530) 756-7317 Fax: (530) 756-7297 *| _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- UDP and ICMP logs not linked? David Bellizzi (Feb 05)
- Re: UDP and ICMP logs not linked? James Hoagland (Feb 06)