Snort mailing list archives
Logging excessive ICMP from HOME_NET
From: "Albert E. Whale" <aewhale () ABS-CompTech com>
Date: Mon, 18 Nov 2002 09:43:52 -0500
I have a considerable amount of ICMP Traffic being logged from ${HOME_NET}. While I recognize that Snort is going to log traffic, but I would prefer that it log the ICMP traffic not from the ${DNS_SERVERS}. Is this possible? -- Albert E. Whale - CISSP http://www.abs-comptech.com ---------------------------------------------------------------------- ABS Computer Technology, Inc. - ESM, Computer & Networking Specialists Sr. Security, Network, and Systems Consultant Board of Directors - InfraGard - Pittsburgh, PA ------------------------------------------------------- This sf.net email is sponsored by: To learn the basics of securing your web site with SSL, click here to get a FREE TRIAL of a Thawte Server Certificate: http://www.gothawte.com/rd524.html _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Logging excessive ICMP from HOME_NET Albert E. Whale (Nov 18)
- Re: Logging excessive ICMP from HOME_NET Erek Adams (Nov 18)