Snort mailing list archives

Building Alert rule


From: May Smith <may24x () yahoo com>
Date: Thu, 7 May 2015 08:28:10 +0000 (UTC)

Hi all,
I'm running CentOS with Snort 2.9.7.2
The box is online just for a couple of days and I can already see that I'm under attackSomebody is hammering against 
port 22 trying to get access.
However, since I'm connecting from various places, my IP keeps changing every time.So adding an IP to an ignore test 
won't help me.
So what I need is to create a rule that sends out an alert if some IP fails to login more than three timesbut won't 
alert if login is successful.
Is that possible ? And if so, how ?
regardsmay
------------------------------------------------------------------------------
One dashboard for servers and applications across Physical-Virtual-Cloud 
Widest out-of-the-box monitoring support with 50+ applications
Performance metrics, stats and reports that give you Actionable Insights
Deep dive visibility with transaction tracing using APM Insight.
http://ad.doubleclick.net/ddm/clk/290420510;117567292;y
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: