[Snort-users] Can't suppress "(snort decoder) Bad Traffic Same Src/Dst IP"

Matt Kettler mkettler at ...4108...
Mon Oct 17 13:34:20 EDT 2005


Mike Kelley wrote:
> I have 2 machines for which this traffic is “normal” I have looked for
> the rule that triggers SPECIFFICALLY this alert … I can’t find it 

This isn't a rule, it's an alert generated directly by the snort decoder itself.

http://www.networksecurityarchive.org/html/Snort-Signatures/2005-09/msg00066.html





More information about the Snort-users mailing list