Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Snort Advanced » sfPortscan

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

sfPortscan


Posted by fatcraniums on March 23, 2005 04:50:17

Good morning,

I am looking for comments on the sfPortscan preprocessor.

I am on a extremely busy network and am required to implement this new feature.
Snort is version 2.3.2.

I need to know if supression of events such as "[snort] portscan: Open Port"
is possible within snort.conf or threshold.conf (realising that they are essentially the same file).

Please let me know if any of you have solved this problem.

Cheers

Posted by Jhewlett on March 25, 2005 11:02:06

A fix for this went into 2.4 and HEAD branches today. Could you check out one of these branches and let me know how it works for you? 2.4 is still considered development, but should be stable to run.