Snort mailing list archives

possible Snort 2.0 bug


From: "Shoshin" <shoshin66 () hotmail com>
Date: Fri, 9 May 2003 00:48:19 -0300

- if I just do LOGGING MODE it works, logging all traffic:
 #snort -vdl /var/log/snort

- if I do IDS MODE it doesnt log any traffic:
 #snort -vdl /var/log/snort -c /etc/snort/snort.conf

** but if I add an alert test rule to snort.conf ( alert tcp any any -> any any )
 and run the same IDS MODE command, then it creates log files and adds to the alert file !!

So what is wrong with IDS MODE, it should be logging traffic even if there are no alerts ????

Current thread: