[Snort-users] Configure and fine tune Snort Rules

Doug Burks doug.burks at ...11827...
Fri Jul 6 07:54:46 EDT 2012


Hi Sujoy,

Please see the following page on the Security Onion wiki:
http://code.google.com/p/security-onion/wiki/ManagingAlerts

If you have additional questions specific to Security Onion, please
feel free to use our mailing list:
http://groups.google.com/group/security-onion

Thanks,
Doug

On Fri, Jul 6, 2012 at 7:43 AM, Sujoy Ghosh <sujoyghosh297 at ...11827...> wrote:
> Hi Team,
> I am using Snort 2.9.2.2 and the snort.conf kinda newer than i am familiar
> with. How do i:
>
> 1. Turn on and off particular rules
> 2. Configure, edit fine tune the rules
>
> I am using Security onion.. it has just # site specific rules and # rules
> downloaded by PulledPork with path pointing to local.rules and
> downloaded.rules respectively.
>
> Thanks,
> Sujoy Ghosh
>
> ------------------------------------------------------------------------------
> Live Security Virtual Conference
> Exclusive live event will cover all the ways today's security and
> threat landscape has changed and how IT managers can respond. Discussions
> will include endpoint security, mobile security and the latest in malware
> threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users
>
> Please visit http://blog.snort.org to stay current on all the latest Snort
> news!



-- 
Doug Burks
http://securityonion.blogspot.com




More information about the Snort-users mailing list