This is a discussion on [Snort-users] not seeing Flow-Portscan messages within the Snort forums, part of the System Security and Security Related category; I have enabled the Flow-Portscan module but I do not see scans in my MySQL db. I do have ...
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
I have enabled the Flow-Portscan module but I do not
see scans in my MySQL db. I do have the portscan preprocessor running and sendng alerts to a flat file. So, I know I am getting scanned.* preprocessor flow-portscan: \ ***** talker-sliding-scale-factor 0.50 \ ***** talker-fixed-threshold 30 \ ***** talker-sliding-threshold 30 \ ***** talker-sliding-window 20 \ ***** talker-fixed-window 30 \ ***** scoreboard-rows-talker 30000 \ ***** server-watchnet [x.x.x.x/xx,x.x.x.x./xx \ ***** server-ignore-limit 200 \ ***** server-rows 65535 \ ***** server-learning-time 7200 \ ***** server-scanner-limit 4 \ ***** scanner-sliding-window 20 \ ***** scanner-sliding-scale-factor 0.50 \ ***** scanner-fixed-threshold 15 \ ***** scanner-sliding-threshold 40 \ ***** scanner-fixed-window 15 \ ***** scoreboard-rows-scanner 30000 \ #**** src-ignore-net [192.168.1.1/32,192.168.0.0/24] \ #**** dst-ignore-net [10.0.0.0/30] \ ***** alert-mode once \ ***** output-mode msg \ ***** tcp-penalties on * * _______________________________ Do you Yahoo!? Declare Yourself - Register online to vote today! http://vote.yahoo.com ------------------------------------------------------- This SF.net email is sponsored by: IT Product Guide on ITManagersJournal Use IT products in your business? Tell us what you think of them. Give us Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more http://productguide.itmanagersjourna...uidepromo.tmpl _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/...fo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.p...st=snort-users |