[Snort-users] Tweaking false positives
erek at ...577...
Fri Sep 21 11:19:01 EDT 2001
On Fri, 21 Sep 2001, kaidhai wrote:
> I am receiving a large number of alerts from a specific machine (DNS) that
> exists in my own LAN and is trusted. I want the alerts for such machines
> (ie, all such false positives) to be reduced. Any answers to that? Thanks
> in advance.
Configure snort. :) Have a look in snort.conf. You'll see the following:
# Define the addresses of DNS servers and other hosts
# if you want to ignore portscan false alarms from them...
var DNS_SERVERS $HOME_NET
# Use portscan-ignorehosts to ignore TCP SYN and UDP "scans" from
# specific networks or hosts to reduce false alerts. It is typical
# to see many false alerts from DNS servers so you may want to
# add your DNS servers here. You can all multiple hosts/networks
# in a whitespace-delimited list.
#preprocessor portscan-ignorehosts: $DNS_SERVERS
Uncomment that line out and all should be fine.
Hope that helps!
More information about the Snort-users