Snort mailing list archives

Realistic maximum priorities


From: Snort User <snort () frenzy org>
Date: Fri, 11 Jul 2003 10:20:58 -0700 (PDT)

  I'm working on integrating snort with some other IDS systems for
correlation purposes. My question involves the priorities snort generates.
I've noticed that none of my generated alerts seem to go past prio 5.

  Is there a logical limit to the max priority that the developers have
set for existing/added bundled rules.
If there isn't one, I'll just chunk everything after 5 together in one big
bunch, but it would be nice if there was more precision.

  Looking at the archives, I couldn't find anything on this topic, so
maybe someone here can help. :)
Thanks a bunch,

Randy

http://www.frenzy.org ICQ: 32276169
"Sed Quis Custodiet Ipsos Custodes?" -Juvenal

This communication (including any attachments) is intended for the use of the intended
recipient only and may contain information that is confidential, privileged or legally
protected. Any unauthorized use or dissemination of this communication is strictly
prohibited. If you have received this communication in error, please immediately notify
the sender by return e-mail message and delete all copies of the original communication.
Thank you for your cooperation.







-------------------------------------------------------
This SF.Net email sponsored by: Parasoft
Error proof Web apps, automate testing & more.
Download & eval WebKing and get a free book.
www.parasoft.com/bulletproofapps1
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: