[Snort-users] Customizing snort rules

simonkc at ...11578... simonkc at ...11578...
Tue Apr 6 03:11:12 EDT 2004

Hi Edin,

I have properly defined the HOME_NET and EXTERNAL_NET variables??
The rules that are getting triggered are SNMP rules.i.e. whenever our NMS
management server polls some devices,the rule triggers.
I want to be able to disable these triggers for some specific IP hosts. The
SNMP rule should not be disabled and continue to look for SNMP traffic.

Thanks and Regards   


-----Original Message-----
From: Edin Dizdarevic [mailto:edin.dizdarevic at ...7509...]
Sent: Tuesday, April 06, 2004 3:15 PM
To: simonkc at ...11578...
Cc: snort-users at lists.sourceforge.net
Subject: Re: [Snort-users] Customizing snort rules


I don't _really_ get your problem: Have you properly defined your 

Could you please specify the rules that trigger?


simonkc at ...11578... schrieb:
> Hi,
> Can anyone point me in the direction of any document explaining how to
> customize snort rules.
> I have a situation wherein the Snort IDS is alerting even for normal SNMP
> requests and traps. How do it disable these alerts for only specific SNMP
> management stations but keep the SNMP rule turned on??
> Thanks and Regards   
> Simon 

Edin Dizdarevic

More information about the Snort-users mailing list