Snort mailing list archives
Re: Log vs Alert
From: "Dusty Hall" <halljer () auburn edu>
Date: Thu, 26 Jun 2003 11:01:24 -0500
I tried this... it logs double the packets. So in ACID you would have two of everything. -Dusty
"list" <list () diverdown cc> 6/26/2003 9:48:37 AM >>>
After reading the link below...can I have snort write both logs and alerts to the database..??? Thanks GSR
On Wed, 25 Jun 2003, Matt Geiger wrote:What is the difference between output database: log and output database: alert? I looked in the readme.database and that was no help. This is a
newbie
question I know, but alert just seems to do more and take longer.http://www.theadamsfamily.net/~erek/snort/logging_methods.txt Cheers! ----- Erek Adams "When things get weird, the weird turn pro." H.S. Thompson ------------------------------------------------------- This SF.Net email is sponsored by: INetU Attention Web Developers & Consultants: Become An INetU Hosting
Partner.
Refer Dedicated Servers. We Manage Them. You Get 10% Monthly
Commission!
INetU Dedicated Managed Hosting http://www.inetu.net/partner/index.php
_______________________________________________
Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
-- Open WebMail Project (http://openwebmail.org) ------------------------------------------------------- This SF.Net email is sponsored by: INetU Attention Web Developers & Consultants: Become An INetU Hosting Partner. Refer Dedicated Servers. We Manage Them. You Get 10% Monthly Commission! INetU Dedicated Managed Hosting http://www.inetu.net/partner/index.php _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users ------------------------------------------------------- This SF.Net email is sponsored by: INetU Attention Web Developers & Consultants: Become An INetU Hosting Partner. Refer Dedicated Servers. We Manage Them. You Get 10% Monthly Commission! INetU Dedicated Managed Hosting http://www.inetu.net/partner/index.php _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Log vs Alert Matt Geiger (Jun 26)
- Re: Log vs Alert Erek Adams (Jun 26)
- Re: Log vs Alert list (Jun 26)
- <Possible follow-ups>
- Re: Log vs Alert Dusty Hall (Jun 26)
- Re: Log vs Alert John Deagan (Jun 26)
- RE: Re: Log vs Alert SRH-Lists (Jun 26)
- Re: Log vs Alert Dusty Hall (Jun 26)
- RE: Re: Log vs Alert John Deagan (Jun 26)
- RE: Re: Log vs Alert John Deagan (Jun 26)
- Re: Log vs Alert Erek Adams (Jun 26)