Snort mailing list archives
Problem getting a snort rule to work
From: "Pennell, Ronald B." <rpennell () ida org>
Date: Thu, 14 Apr 2005 08:58:46 -0400
I'm extremely new to snort and have been trying to get a simple snort rule to work. I'm task with grabbing an alert for every email message that is going outbound from my organization. I've tried using the following local rule: Alert tcp $SMTP_NET --> any 25 Alert udp " " " Alert tcp $HOME_Net " " When I check the acid viewer, I see no traffic at all. Any help would be greatly appreciated. Ron Pennell rpennell () ida org
Current thread:
- Problem getting a snort rule to work Pennell, Ronald B. (Apr 14)
- <Possible follow-ups>
- RE: Problem getting a snort rule to work Briggs, Bruce (Apr 14)