Snort
Here I would like to share my experience with "Snort IDS"
Sunday, 5 January 2014
Ignore a specific alert for specific IP address in Snort
If we want to ignore a specific snort rule for specific IP or network, we can use "suppression" in threshold.conf file under /etc/snort.
[root@snort rules]# vim /etc/snort/threshold.conf
No comments:
Post a Comment
Older Post
Home
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment