Snort - the de facto standard for intrusion detection/prevention
next up previous contents
Next: Format Up: Output Modules Previous: Format   Contents

alert_full

This will print Snort alert messages with full packet headers. The alerts will be written in the default logging directory (/var/log/snort) or in the logging directory specified at the command line.

Inside the logging directory, a directory will be created per IP. These files will be decoded packet dumps of the packets that triggered the alerts. The creation of these files slows Snort down considerably. This output method is discouraged for all but the lightest traffic situations.



Subsections

Steven Sturges 2007-05-11