Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Rules » Newbie Rule Questions

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

Newbie Rule Questions


Posted by mpapet on May 03, 2005 09:52:19

Hello,

I'm getting what I think are false alarms originate from one client inside our LAN to another client inside our LAN.(Windows boxes)

1-Do I supress these alarms by modifying rules to ignore client-to-client detection?
1a- Is it wise for me to do this?
2- Can anyone recommend a book with good rule-writing instructions


Posted by nigel on May 03, 2005 17:38:12

First, reading material:

http://www.snort.org/docs/

Now, you need to make sure you have first defined the variables that are pertinent to your setup in snort.conf before you start "tuning" out any events. You have a lot of reading to do first though.