[Snort-users] Portscan Traffic?

Daniél Haslinger daniel.haslinger at ...9693...
Mon Aug 11 23:01:02 EDT 2003


Do you mean you just want to have portscans logged or 
you want to know how much traffic the portscans produced?

For the first case just enable the integrated Portscan PreProcessor
(there are 2 types, PortScan and PortScan2)

it logs portscans on your triggers to your desired file.

hope that helps !


     Daniél Haslinger
      Security & Engineering 

--------------------------------------------------------------------------------

      :: Rotheneder GmbH Schillerplatz 1 - A 3100 St.Pölten 
      :: eMail daniel.haslinger at ...9693... 
      :: website http://www.rotheneder.com 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20030811/8b84a46e/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.gif
Type: image/gif
Size: 487 bytes
Desc: not available
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20030811/8b84a46e/attachment.gif>


More information about the Snort-users mailing list