|
|
|
|
Snort Forums Archive
Archive Home » Snort Advanced » sfPortscan
Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.
[ Notice: Full Version of This Topic ]
sfPortscan
Posted by fatcraniums on March 23, 2005 04:50:17
Good morning,
I am looking for comments on the sfPortscan preprocessor.
I am on a extremely busy network and am required to implement this new feature.
Snort is version 2.3.2.
I need to know if supression of events such as "[snort] portscan: Open Port"
is possible within snort.conf or threshold.conf (realising that they are essentially the same file).
Please let me know if any of you have solved this problem.
Cheers |
|
Posted by Jhewlett on March 25, 2005 11:02:06
A fix for this went into 2.4 and HEAD branches today. Could you check out one of these branches and let me know how it works for you? 2.4 is still considered development, but should be stable to run.
|
|
|
|
|
|