[Snort-users] Snort Usage.

Ralf Hildebrandt Ralf.Hildebrandt at ...821...
Wed Mar 14 01:21:04 EST 2001


On Wed, Mar 14, 2001 at 04:11:26PM +1100, ceenine at ...1488... wrote:

> Can anyone help me on how to use Snort. I've actually installed it but 
> now don't know how to use it. Do i have to run it in Cron? sorry it's 
> not a tech question, but i really don't know where to start.

Snort is normally started at boot time and scans the whole network traffic.
It protocols to syslog by default.
 
> Also, A new user has been added to box "Snort" -- why?? can i delete 
> it? is it safe to keep it??

I guess snort is supposed to run as this unprivileged user. This is to avoid
having root privileges, should a compromise of snort occur.

-- 
ralf.hildebrandt at ...821...
System Engineer                                            innominate AG
Diplom-Informatiker                                 the linux architects
tel: +49.30.308806-62  fax: -698                      www.innominate.com




More information about the Snort-users mailing list