[Snort-users] HTTP 304 alerts

Dionyssios Edwards dedwards at ...15843...
Mon Sep 24 14:18:29 EDT 2012


I'm having a lot of HTTP 304 alerts on my snort box. The source is mostly from deploy.akamaitechnologies.com which I assume is windows update services. Is there any way I can set the snort box to ignore these alerts for those *.deploy.akamaitechnologies.com. Ignoring traffic based on FQDN vs. IP addresses is something I haven't been able to figure out yet on snort. I'm very new to it.

Thanks in advance



[cid:finalsrasignaturelogo53f9.png]


Dionyssios Edwards
DP Prog Analyst
Maryland State Retirement and Pension System
120 East Baltimore Street | Baltimore, MD | 21202-6700
Tel:  410-625-5563 | 1-800-492-5909 | TDD/TTY 410-625-5535
sra.maryland.gov<http://www.sra.maryland.gov/>










-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20120924/a5b080ff/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: finalsrasignaturelogo53f9.png
Type: image/png
Size: 10748 bytes
Desc: finalsrasignaturelogo53f9.png
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20120924/a5b080ff/attachment.png>


More information about the Snort-users mailing list