Snort mailing list archives
Re: Snort Rules Question
From: Jose Maria Lopez <jkerouac () bgsec com>
Date: 07 Sep 2004 20:53:24 +0200
El mar, 07 de 09 de 2004 a las 19:27, Scott Elgram escribió:
Hello, I have people logging on to my network from out side the firewall. Snort keeps logging all traffic back and forth through this connection which is resulting in 1000's of records. Does anyone know of a way I can have Snort only log this connection once? -Scott
Use the file /etc/snort/threshold.conf, it's the solution for your problem. It's well commented so you it should be possible to configure it without further documentation. -- Jose Maria Lopez Hernandez Director Tecnico de bgSEC jkerouac () bgsec com bgSEC Seguridad y Consultoria de Sistemas Informaticos http://www.bgsec.com ESPAÑA The only people for me are the mad ones -- the ones who are mad to live, mad to talk, mad to be saved, desirous of everything at the same time, the ones who never yawn or say a commonplace thing, but burn, burn, burn like fabulous yellow Roman candles. -- Jack Kerouac, "On the Road" ------------------------------------------------------- This SF.Net email is sponsored by BEA Weblogic Workshop FREE Java Enterprise J2EE developer tools! Get your free copy of BEA WebLogic Workshop 8.1 today. http://ads.osdn.com/?ad_idP47&alloc_id808&op=click _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Snort Rules Question Scott Elgram (Sep 07)
- Re: Snort Rules Question Jose Maria Lopez (Sep 07)
- <Possible follow-ups>
- Re: Snort Rules Question Lyndon Tiu (Sep 07)