snort_2.9.6.1_centos_6.5
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revisionNext revisionBoth sides next revision | ||
snort_2.9.6.1_centos_6.5 [2014/05/08 20:03] – [Configure Snort] admin | snort_2.9.6.1_centos_6.5 [2014/05/09 07:11] – [Test rule] admin | ||
---|---|---|---|
Line 16: | Line 16: | ||
</ | </ | ||
Copy any dynamic rulesets you have or are using to the above directory. | Copy any dynamic rulesets you have or are using to the above directory. | ||
+ | |||
+ | ====Test rule==== | ||
+ | Put as last line in snot.conf | ||
+ | alert icmp any any -> 1.2.3.4 any (msg: " | ||
+ | |||
+ | Find the alerts in the log | ||
+ | < | ||
+ | 05/ | ||
+ | 05/ | ||
+ | 05/ | ||
+ | 05/ | ||
+ | </ | ||
+ | |||
+ | You can even show contents of the packets with tcpdump | ||
+ | tcpdump -r snort.log.1399615922 | ||
+ | |||
snort_2.9.6.1_centos_6.5.txt · Last modified: 2021/10/09 15:14 by 127.0.0.1