Snort mailing list archives
reading a new rule.
From: "samwun" <samwun () hgcbroadband com>
Date: Sun, 10 Aug 2003 23:43:11 +0800
Dear all, I've just created a new rule for snort 2.0, but I don't how to run snort commandline to execute this rule. Here is the step I did: 1. added the name of the rule in the /usr/local/snort.2.0.0/etc/snort.conf. 2. execute snort command: snort -c /usr/local/snort.2.0.o/etc/snort.conf By the way, is there any way to test the current snort rule? Eg. Simulate attacks. Thanks Sam
Current thread:
- reading a new rule. samwun (Aug 10)
- Re: reading a new rule. Erek Adams (Aug 10)
- RE: reading a new rule. samwun (Aug 10)
- RE: reading a new rule. Erek Adams (Aug 11)
- RE: reading a new rule. samwun (Aug 12)
- can't execute a rule. samwun (Aug 13)
- capture any packet with an none-continue ID number samwun (Aug 13)
- Re: capture any packet with an none-continue ID number Erek Adams (Aug 13)
- Re: capture any packet with an none-continue ID number Matt Kettler (Aug 13)
- RE: reading a new rule. samwun (Aug 10)
- Re: reading a new rule. Erek Adams (Aug 10)
