[Snort-users] question

james hackerwacker at ...3784...
Mon May 26 18:58:05 EDT 2003

I run a seperate Snort process, "snortrecon",  with a seperate 
snort.conf. There I can modify my HOME_NET and other vars
to be specific to the nets I am watching. This allows me to run
rules that might be too noisy if used in my main snort process, 
watching my entire network. Makes mucking through the logs 


