Snort mailing list archives

Snort Check and Rules 'Best Practice'


From: "Derrick Lichti" <dlichti () mitra com>
Date: Thu, 14 Nov 2002 10:39:30 -0500

Hello;
 
I'm wondering if there is a way to check and see how many packets Snort is dropping, if any, while it is still running. 
I think I might be losing packets but I'm not sure (ie. when MSN Messenger was spammed last night, multiple users were 
received messages and only one of them appeared in the Snort logs)!
 
And, I'm looking for the best way to update my rules but keep all the changes the I have made. I've seen Snortcenter, 
does it allow this? I've made many modifications to the rules themselves and I would like to avoid having to re-update 
everything individually.
 
I use FreeBSD 4.6.2, MySQL 3.23.51, Acid 0.9.6b22, PHP 4.2.3, Snort 1.9.0.
 
Thanks!
Derrick

Current thread: