[Snort-users] question

james hackerwacker at ...3784...
Mon May 26 18:58:05 EDT 2003


I run a seperate Snort process, "snortrecon",  with a seperate 
snort.conf. There I can modify my HOME_NET and other vars
to be specific to the nets I am watching. This allows me to run
rules that might be too noisy if used in my main snort process, 
watching my entire network. Makes mucking through the logs 
easier.

james 




More information about the Snort-users mailing list