Snort mailing list archives

Re: FIltering out Internal Mail Logging


From: Mark.Schutzmann () Omron com
Date: Tue, 16 Mar 2004 12:48:53 -0600


Frank,

You can find all the information that you need at http://www.snort.org and
if you really want to learn about it, I highly recommend the book "Snort
2.0 Detection" by Brian Caswell, et al, by Syngress Press.


                                                                                                                        
                          
                      <frank.hodits () skipjack com>                                                                    
                             
                      Sent by:                            To:       <snort-users () lists sourceforge net>              
                             
                      snort-users-admin () lists sour        cc:                                                        
                             
                      ceforge.net                         Subject:  [Snort-users] FIltering out Internal Mail Logging   
                          
                                                                                                                        
                          
                                                                                                                        
                          
                      03/12/2004 10:12 AM                                                                               
                          
                                                                                                                        
                          
                                                                                                                        
                          







I am running Snort 2.0.  We have it running in IDS mode.  The logs keep
getting full of internal traffic.  I am a rookie at creating rules and need
some advice.  Are there default rules that I can download that have the
most recent security threats?





Thanks,


Frank





---
Incoming mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.620 / Virus Database: 399 - Release Date: 3/11/2004





---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.620 / Virus Database: 399 - Release Date: 3/11/2004










-------------------------------------------------------
This SF.Net email is sponsored by: IBM Linux Tutorials
Free Linux tutorial presented by Daniel Robbins, President and CEO of
GenToo technologies. Learn everything from fundamentals to system
administration.http://ads.osdn.com/?ad_id=1470&alloc_id=3638&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: