Andreas Krennmair writes:

> Hello!
> Would it be possible to implement a commandline switch for snort so
> that it throws away all attacks it recognizes and leaves the rest,
> i.e. all the regular traffic and unknown attacks.

Switch all rules that you don't want to pass rules, use the -o option
and then add a

log ip any any -> any any to the end of your snort.conf
