sb ch chulmin22 at ...125...
Sun Jun 15 19:31:07 EDT 2003

Hello, all.

I would like to disable this function, but I can't find any rule file 
So this alert has nothing related rule files.
How can I disable this logging?
Surely, I did like below, but alerts are continued.

var HOME_NET any ![210.xx.xx.xxx]
var EXTERNAL_NET any ![210.xx.xx.xxx] 

[**] [116:97:1] (snort_decoder): Short UDP packet, length field > payload 
length [**]
06/16-11:16:14.651421 210.xx.xx.xxx:0 -> xxx.xxx.145.78:0
UDP TTL:254 TOS:0x0 ID:40445 IpLen:20 DgmLen:2596
Len: 2568

Thanks in advance.

