Bluehost.com Web Hosting $6.95

[Snort-users] not seeing Flow-Portscan messages

This is a discussion on [Snort-users] not seeing Flow-Portscan messages within the Snort forums, part of the System Security and Security Related category; I have enabled the Flow-Portscan module but I do not see scans in my MySQL db. I do have ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 10-20-2004
Larry Wichman
 
Posts: n/a
Default [Snort-users] not seeing Flow-Portscan messages

I have enabled the Flow-Portscan module but I do not
see scans in my MySQL db. I do have the portscan
preprocessor running and sendng alerts to a flat file.
So, I know I am getting scanned.*

preprocessor flow-portscan: \

***** talker-sliding-scale-factor 0.50 \

***** talker-fixed-threshold 30 \

***** talker-sliding-threshold 30 \

***** talker-sliding-window 20 \

***** talker-fixed-window 30 \

***** scoreboard-rows-talker 30000 \

***** server-watchnet [x.x.x.x/xx,x.x.x.x./xx \

***** server-ignore-limit 200 \

***** server-rows 65535 \

***** server-learning-time 7200 \

***** server-scanner-limit 4 \

***** scanner-sliding-window 20 \

***** scanner-sliding-scale-factor 0.50 \

***** scanner-fixed-threshold 15 \

***** scanner-sliding-threshold 40 \

***** scanner-fixed-window 15 \

***** scoreboard-rows-scanner 30000 \

#**** src-ignore-net [192.168.1.1/32,192.168.0.0/24] \

#**** dst-ignore-net [10.0.0.0/30] \

***** alert-mode once \

***** output-mode msg \

***** tcp-penalties on

*

*





_______________________________
Do you Yahoo!?
Declare Yourself - Register online to vote today!
http://vote.yahoo.com


-------------------------------------------------------
This SF.net email is sponsored by: IT Product Guide on ITManagersJournal
Use IT products in your business? Tell us what you think of them. Give us
Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more
http://productguide.itmanagersjourna...uidepromo.tmpl
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 03:54 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0