Snort mailing list archives
Snort Configuration
From: Luís Vitório Cargnini <vitorio () digitel com br>
Date: 19 Sep 2003 17:27:47 -0300
Exist an way to configurate snort to don't sent the message of alarm ??
i don't want to receive in syslog the message, but only the code of the
message 1631
example:
this is what i receive now
Sep 19 10:15:38 192.168.1.7 snort: [1:1633:4] CHAT AIM receive message
[Classification: Potential Corporate Privacy Violation] [Priority: 1]:
{TCP} 64.12.26.84:5190 -> 192.168.1.160:43357
i want to receive in this form:
Sep 19 10:15:38 192.168.1.7 snort: [1:1633:4] 1633 [Classification:
Potential Corporate Privacy Violation] [Priority: 1]: {TCP}
64.12.26.84:5190 -> 192.168.1.160:43357
1633 || CHAT AIM receive message
thanks and regards.
Attachment:
signature.asc
Description: This is a digitally signed message part
Current thread:
- Snort Configuration Luís Vitório Cargnini (Sep 19)
