Snort mailing list archives
Snort Check and Rules 'Best Practice'
From: "Derrick Lichti" <dlichti () mitra com>
Date: Thu, 14 Nov 2002 10:39:30 -0500
Hello; I'm wondering if there is a way to check and see how many packets Snort is dropping, if any, while it is still running. I think I might be losing packets but I'm not sure (ie. when MSN Messenger was spammed last night, multiple users were received messages and only one of them appeared in the Snort logs)! And, I'm looking for the best way to update my rules but keep all the changes the I have made. I've seen Snortcenter, does it allow this? I've made many modifications to the rules themselves and I would like to avoid having to re-update everything individually. I use FreeBSD 4.6.2, MySQL 3.23.51, Acid 0.9.6b22, PHP 4.2.3, Snort 1.9.0. Thanks! Derrick
Current thread:
- Snort Check and Rules 'Best Practice' Derrick Lichti (Nov 14)
- Re: Snort Check and Rules 'Best Practice' Erek Adams (Nov 14)