[Snort-users] Snort Rules Question

Jose Maria Lopez jkerouac at ...12346...
Tue Sep 7 12:08:01 EDT 2004


El mar, 07 de 09 de 2004 a las 19:27, Scott Elgram escribió:
> Hello,
>     I have people logging on to my network from out side the
> firewall.  Snort keeps logging all traffic back and forth through this
> connection which is resulting in 1000's of records.  Does anyone know
> of a way I can have Snort only log this connection once?
>  
> -Scott

Use the file /etc/snort/threshold.conf, it's the solution for
your problem. It's well commented so you it should be possible
to configure it without further documentation.


-- 
Jose Maria Lopez Hernandez
Director Tecnico de bgSEC
jkerouac at ...12346...
bgSEC Seguridad y Consultoria de Sistemas Informaticos
http://www.bgsec.com
ESPAÑA

The only people for me are the mad ones -- the ones who are mad to live,
mad to talk, mad to be saved, desirous of everything at the same time,
the ones who never yawn or say a commonplace thing, but burn, burn, burn
like fabulous yellow Roman candles.
                -- Jack Kerouac, "On the Road"





More information about the Snort-users mailing list