Snort
Here I would like to share my experience with "Snort IDS"
Sunday, 5 January 2014
Ignore a specific alert for specific IP address in Snort
If we want to ignore a specific snort rule for specific IP or network, we can use "suppression" in threshold.conf file under /etc/snort.
[root@snort rules]# vim /etc/snort/threshold.conf
Newer Posts
Older Posts
Home
Subscribe to:
Posts (Atom)