This is a discussion on [Snort-users] alert_unified only within the Snort forums, part of the System Security and Security Related category; This is a MIME message. If you are reading this text, you may want to consider changing to a mail ...
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
This is a MIME message. If you are reading this text, you may want to
consider changing to a mail reader or gateway that understands how to properly handle MIME multipart messages. --=_D58B9CF9.5A3B7617 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Hello- I've moved to barnyard for inserting events into my db which works really slick. With that, I only include the alert_unified output module for snort.conf (snip from snort.conf )output alert_unified: filename snort.alert, limit 128 In my log directory however, I still see what looks like the alerrt_full module output, ie directories created with IP addr for the name. I would like to turn that off so I dont have to do a lot of clean up file maintainace on my sensors. Thanks, John B --=_D58B9CF9.5A3B7617 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: 8bit Content-Description: HTML <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <HTML><HEAD> <META http-equiv=Content-Type content="text/html; charset=iso-8859-1"> <META content="MSHTML 6.00.2800.1170" name=GENERATOR></HEAD> <BODY style="MARGIN-TOP: 2px; FONT: 12pt Times New Roman; MARGIN-LEFT: 2px"> <DIV>Hello-</DIV> <DIV>I've moved to barnyard for inserting events into my db which works really slick. With that, I only include the alert_unified output module for snort.conf </DIV> <DIV> </DIV> <DIV>(snip from snort.conf )output alert_unified: filename snort.alert, limit 128<BR><BR>In my log directory however, I still see what looks like the alerrt_full module output, ie directories created with IP addr for the name. I would like to turn that off so I dont have to do a lot of clean up file maintainace on my sensors.<BR></DIV> <DIV>Thanks,</DIV> <DIV>John B<BR></DIV></BODY></HTML> --=_D58B9CF9.5A3B7617-- ------------------------------------------------------- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/...fo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.p...st=snort-users |