Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: [Snort-sigs] general sig question

From: Brian <bmc(at)snort.org>
Date: Thu May 22 2003 - 08:00:28 EDT

On Thu, May 22, 2003 at 02:03:17AM -0400, d_greenjr wrote:
> Is there a way to have a rule alert-and/or log-only after the rule has been detected n amount of times from a specific source?

You can't do that in snort right now as we do not have thresholding support.

-brian



This SF.net email is sponsored by: ObjectStore. If flattening out C++ or Java code to make your application fit in a relational database is painful, don't do it! Check out ObjectStore. Now part of Progress Software. http://www.objectstore.net/sourceforge

Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs Received on Thu May 22 08:50:09 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:08:29 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library