[Snort-users] ignore a single host
isp at ...12699...
Mon Nov 22 08:40:21 EST 2004
Can't quit figure out how to ignore a single computer.
I have a computer which continuously gets following alert. It is because it
is making lots of SNMP requests which is what it is suppose to do. How do I
get snort to ignore a single host like this or just ignore this particular
[**] [1:1417:9] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
11/21-03:37:59.626234 220.127.116.11:53965 -> 18.104.22.168:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:118 DF
More information about the Snort-users