Snort mailing list archives

Several newbie questions


From: "Nall, Robert" <rnall () co riley ks us>
Date: Thu, 13 Feb 2003 10:42:20 -0600

Hello all!!

1. Rules processing: If a packet sets off one rule, does the packet still
get processed by the other rules?
2. Packet type: Does "IP" cover TCP, UDP, & ICMP or is something left out
that I need to include?
3. ACID w/MySQL Database: How can I get the data moved to the "archive"
database faster than using ACID "move" command?

Snort 1.90 on win2k srv
Acid (lastest build)
Etc... Etc... (mine works, now just trying to tweak and modify)

 
__________________________________________
Robert Nall
Network Administrator
Riley County - Information Systems 
110 Courthouse Plaza 
Manhattan, KS 66502 
Phone: (785) 537-6309
Cell: (785) 313-9003 
Fax: (785) 537-6306 
Email: rnall () co riley ks us 

Current thread: