Snort mailing list archives

multiple ASN.1,Null scan alerts


From: Always Bishan <bishan4u () yahoo co uk>
Date: Tue, 11 Mar 2003 15:04:34 +0000 (GMT)

hi

I used nessus to scan my network with snort running.

Then Snort alerts on the activity by Nessus.But gives
a lot of alerts of the same type.

for e.g. for same set of destination and source ip
address and port nos. it gives multiple ASN.1 , NULL
scans, Stealth scans.

Now my point is how can I tell snort to alert only
once for same set of source and destination?

so that I don't get multiple alerts of the same type.

Regards,
Bishan

=====
Celebrating Happinessemail: bishan@sumerusolutions.comcompany: www.sumerusolutions.com

__________________________________________________
Do You Yahoo!?
Everything you'll ever need on one web page
from News and Sport to Email and Music Charts
http://uk.my.yahoo.com


-------------------------------------------------------
This SF.net email is sponsored by:Crypto Challenge is now open! 
Get cracking and register here for some mind boggling fun and 
the chance of winning an Apple iPod:
http://ads.sourceforge.net/cgi-bin/redirect.pl?thaw0031en
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: