Snort mailing list archives

Re: test a threshold rule, please?


From: "Chris Reid" <chris.reid () codecraftconsultants com>
Date: Thu, 5 Aug 2004 22:42:16 -0600

As Rich said, he and I have exchanged private e-mails on this matter.  Rich
has tested a fix for us, and this fix has already been committed to CVS.
Thanks to everyone who helped!

Chris Reid

----- Original Message ----- 
From: "Rich Adamson" <radamson () routers com>
To: "sekure" <sekure () gmail com>
Cc: "Snort Users Postings" <snort-users () lists sourceforge net>
Sent: Thursday, August 05, 2004 9:45 PM
Subject: Re: [Snort-users] test a threshold rule, please?


Apparently the problem was a Win32 specifc issue that Chris rsolved. He
sent a
private email with an executable that addressed the issue, and its now
working
just fine. The seconds and count parameters in the example were intended
to
generate some sample alerts, which it did following the fix. I've since
increased
those thresholds to realistic numbers. :)

Rich




-------------------------------------------------------
This SF.Net email is sponsored by OSTG. Have you noticed the changes on
Linux.com, ITManagersJournal and NewsForge in the past few weeks? Now,
one more big change to announce. We are now OSTG- Open Source Technology
Group. Come see the changes on the new OSTG site. www.ostg.com
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: