Snort mailing list archives

Snort sensor IDs


From: "Mitchell, Jason" <jason.mitchell () seattlechildrens org>
Date: Wed, 18 Aug 2004 16:51:06 -0700

I'm left a bit confused over how Snort handles assigning sensor IDs and how
I might be able to control it.  For example, I just changed how Snort runs,
and in doing so, a new sensor ID is created and dumps the data in there,
which makes querying MySql from a front end annoying.
 
Anyone know how to keep Snort to just a single sensor ID regardless of any
changes I might make to the startup options?  Or is there something inherent
that would make that a really bad idea?
 
On the same note, is it possible to dump data from multiple interfaces into
a single "sensor"?  I don't really care which sensor picked up the data as I
can look at source/destination anyway.
 
-Jason

CONFIDENTIALITY NOTICE: This e-mail message, including any attachments, is for the sole use of the intended 
recipient(s) and may contain confidential, proprietary, and/or privileged information protected by law. If you are not 
the intended recipient, you may not use, copy, or distribute this e-mail message or its attachments. If you believe you 
have received this e-mail message in error, please contact the sender by reply e-mail and destroy all copies of the 
original message. 

Current thread: