Snort - the de facto standard for intrusion detection/prevention
next up previous
Next: 3.12 How do you Up: 3 Configuring Snort Previous: 3.10 How do I

3.11 Why are there no subdirectories under /var/log/snort for IP addresses?

It depends on how your snort configuration logs. If it logs in binary format, you'll have to process the binary log in order to get cleartext.