Snort mailing list archives

Re: Unknown POP3 Command


From: James Lay <jlay () slave-tothe-box net>
Date: Wed, 05 Jun 2013 11:46:07 -0600

On 2013-06-05 09:28, Josh Bitto wrote:
The only problem with doing a pcap is we use pfsense (open source
firewall) and it has snort built into it. There is a way to do a pcap
for the offending IP's, but doing it continuously isn't going to
happen. I'm already having memory issues with the amount of sensors 
we
have and each one using high amount of memory.


Josh,

What do your output plugins show in your snort.conf?

James

------------------------------------------------------------------------------
How ServiceNow helps IT people transform IT departments:
1. A cloud service to automate IT design, transition and operations
2. Dashboards that offer high-level views of enterprise services
3. A single system of record for all IT processes
http://p.sf.net/sfu/servicenow-d2d-j
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: