[Snort-users] Snort rules help

Pat McNamara pmcnamara at ...14830...
Tue Jun 8 09:07:42 EDT 2010

Hi all,

I am getting may false alerts (spp_ssh) Protocol mismatch from 1  
machine we use to scan our machines for open ports. I have tried  
everything I can think of so as not too have these alerts show up in  
BASE. All the alertds come from 1 IP Address so is there anything I  
can do so that they don't get written to the DB.


Pat McNamara
IT Systems Administrator
.NU domain, Ltd.
Worldnames, Inc.
+1-508-359-5600 x116
pmcnamara at ...14830...

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20100608/719cc81a/attachment.html>

More information about the Snort-users mailing list