Snort mailing list archives

Re: alert_unified only


From: Erek Adams <erek () snort org>
Date: Thu, 2 Oct 2003 19:09:02 -0400 (EDT)

On Wed, 1 Oct 2003, John Byrnes wrote:

I've moved to barnyard for inserting events into my db which works
really slick. With that, I only include the alert_unified output module
for snort.conf

(snip from snort.conf )output alert_unified: filename snort.alert,
limit 128

In my log directory however, I still see what looks like the
alerrt_full module output, ie directories created with IP addr for the
name. I would like to turn that off so I dont have to do a lot of clean
up file maintainace on my sensors.


From

        snort -\?
[...]
        -N         Turn off logging (alerts still work)
[...]

Cheers!

-----
Erek Adams

   "When things get weird, the weird turn pro."   H.S. Thompson


-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: