Snort - the de facto standard for intrusion detection/prevention
next up previous
Next: 4.20 What is the Up: 4 Rules and Alerts Previous: 4.18 I am getting

4.19 How do I test Snort alerts and logging?

Try a rule that will fire off all the time like:

alert tcp any any -> any any (msg:"TCP traffic";)

Also take a look at sneeze at http://snort.sourceforge.net/sneeze-1.0.tar Sneeze is a false positive generator that reads snort signatures and generates packets that will trigger the rules.



Nigel Houghton 2006-10-02