[Snort-users] http insect
cadams at ...11235...
Thu Feb 19 06:37:24 EST 2004
I have been running snort (with ACID) for a while and have had no
problems but I recently upgraded one of my sensors to Snort version
2.1.0 and I have been getting tons of http\_inspect alerts. These alerts
are from my internal network and I know the items in it are ok so how
can I get rid of these false positives? I can not seem to find any rule
that contains these but I may just be missing it. Could someone please
point me in the right direction?
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Snort-users