[Snort-users] Intrusion Detection with Snort

Fyodor fygrave at ...121...
Thu Oct 5 20:02:32 EDT 2000


On Thu, Oct 05, 2000 at 03:40:57PM +0100, Nuno Miguel Neves wrote:
> 
> Hi.
> 
> I'm using snort-1.6.3-patch2.
> 
> What is the correct command line to make snort act as an intrusion detector.
> 
> 
> I ran with "snort -d -l /var/log/snort -M machines -c snort-lib" and then
> from another subnet, I did a nmap -sT -O host, but snort didn't give any
> alert! :-(
> 

check out alert file in /var/log/snort, if alerts are there and you're not
seeing them popped on your windows workstations, it's very likely a problem of
your smbclient setup. it should be in PATH and you should be able to send
messages by hand using -M switch.



More information about the Snort-users mailing list