[Snort-users] Intrusion Detection with Snort

Fyodor fygrave at ...121...
Thu Oct 5 20:02:32 EDT 2000

On Thu, Oct 05, 2000 at 03:40:57PM +0100, Nuno Miguel Neves wrote:
> Hi.
> I'm using snort-1.6.3-patch2.
> What is the correct command line to make snort act as an intrusion detector.
> I ran with "snort -d -l /var/log/snort -M machines -c snort-lib" and then
> from another subnet, I did a nmap -sT -O host, but snort didn't give any
> alert! :-(

check out alert file in /var/log/snort, if alerts are there and you're not
seeing them popped on your windows workstations, it's very likely a problem of
your smbclient setup. it should be in PATH and you should be able to send
messages by hand using -M switch.

More information about the Snort-users mailing list