Snort mailing list archives

Re: Packets being alerted with other hosts, but not the localhost with Snort on it


From: John Byrne via Snort-users <snort-users () lists snort org>
Date: Mon, 10 Sep 2018 16:43:06 -0700

Yeah…  That didn’t work.  Are you toying with me like all of the hackers on my network?  and what do you mean by 
t-bird?  I didn’t quite understand that.

Here’s my command line, so you can give it to more hackers to know how I’m running my setup so they can do some more 
damage.  ; )

(before your suggestion)
snort -c /etc/snort/snort.conf -i eth0 -l /var/log
(after your suggestion)
snort -k none -c /etc/snort/snort.conf -i eth0 -l /var/log

Curiously,
John

On Sep 10, 2018, at 5:52 AM, wkitty42 () windstream net wrote:

On 09/09/2018 09:02 PM, John Byrne wrote:
Oops…
I accidentally replied to just wkitty42…
This message is going to both wkitty42 and the snort user list.
Sorry about that… I just clicked on reply and assumed it would go to the snort user list.


yeah, i use "reply all" in my t-bird ;)


i do not recall you showing your snort command line... if you do not have it in place, try adding "-k none" to your 
command line and see if that helps...


-- 
NOTE: No off-list assistance is given without prior approval.
      *Please keep mailing list traffic on the list unless*
      *a signed and pre-paid contract is in effect with us.*

_______________________________________________
Snort-users mailing list
Snort-users () lists snort org
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

        To unsubscribe, send an email to:
        snort-users-leave () lists snort org

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Current thread: