Snort mailing list archives
Snort sensor IDs
From: "Mitchell, Jason" <jason.mitchell () seattlechildrens org>
Date: Wed, 18 Aug 2004 16:51:06 -0700
I'm left a bit confused over how Snort handles assigning sensor IDs and how I might be able to control it. For example, I just changed how Snort runs, and in doing so, a new sensor ID is created and dumps the data in there, which makes querying MySql from a front end annoying. Anyone know how to keep Snort to just a single sensor ID regardless of any changes I might make to the startup options? Or is there something inherent that would make that a really bad idea? On the same note, is it possible to dump data from multiple interfaces into a single "sensor"? I don't really care which sensor picked up the data as I can look at source/destination anyway. -Jason CONFIDENTIALITY NOTICE: This e-mail message, including any attachments, is for the sole use of the intended recipient(s) and may contain confidential, proprietary, and/or privileged information protected by law. If you are not the intended recipient, you may not use, copy, or distribute this e-mail message or its attachments. If you believe you have received this e-mail message in error, please contact the sender by reply e-mail and destroy all copies of the original message.
Current thread:
- Snort sensor IDs Mitchell, Jason (Aug 18)
- RE: Snort sensor IDs Jeff Dell (Aug 19)