[Snort-users] HTTP 304 alerts

waldo kitty wkitty42 at ...14940...
Wed Sep 26 00:02:04 EDT 2012


On 9/24/2012 14:18, Dionyssios Edwards wrote:
> I’m having a lot of HTTP 304 alerts on my snort box. The source is mostly from
> deploy.akamaitechnologies.com which I assume is windows update services. Is
> there any way I can set the snort box to ignore these alerts for those
> *.deploy.akamaitechnologies.com. Ignoring traffic based on FQDN vs. IP addresses
> is something I haven’t been able to figure out yet on snort. I’m very new to it.

there is no way to ignore FQDNs... snort works on IPs...





More information about the Snort-users mailing list