[Snort-users] snort.conf vs vision.conf

dotslash dotslash at ...1760...
Sun Apr 22 05:16:37 EDT 2001


if i use vision.conf (coz i'm using vision.rules -- so kinda make it
uniform) will i be missing something that snort.conf (and it's rules) uses?
i tend to like the vision files as i can look up the IDS number and see what
it means.

i know i could merge them but i still feel quesy about the idea.  for one
thing, why is it that there's a preprocessor for http-decode 80 8080 in
snort.conf and in vision.conf it's only for 80?

regards,





More information about the Snort-users mailing list