[Snort-users] Regarding IDS rules.

Ashley Thomas athomas at ...3539...
Sat Mar 9 21:04:02 EST 2002


Hi all,

Is it possible / Is it good / to have multiple rules that might be matched
for a packet/event.

I mean, when the IDS processes the packet,i could trigger more than one
rule, right ?

Ideally that is not desired, right ?
But practically when using Snort does this happen ?

Has anyone experienced something similar ?

thanks
Ashley





More information about the Snort-users mailing list