Thu Nov 23 16:36:19 EST 2017
will only do one variable substitution per line. I'm
not sure, though; that's not my code.
The thresholds are not used for ignorehosts. But remember
that any TCP stealth packets will always trip a scan
detection from an ignorehost.
Try doing the listing in one line and tell me if that
works. Also, you don't have to have the "/32" netmask
for a single host. It'll work fine, but you can have
just the IP address.
More information about the Snort-users