[Snort-devel] snort feature request

Chris Green cmg at ...835...
Sun Mar 31 18:31:13 EST 2002


Andreas Krennmair <ak at ...896...> writes:

> Hello!
>
> Would it be possible to implement a commandline switch for snort so
> that it throws away all attacks it recognizes and leaves the rest,
> i.e. all the regular traffic and unknown attacks.


Switch all rules that you don't want to pass rules, use the -o option
and then add a

log ip any any -> any any to the end of your snort.conf
--
Chris Green <cmg at ...835...>
A good pun is its own reword.




More information about the Snort-devel mailing list