| To: | <snort-users@lists.sourceforge.net> |
|---|---|
| Subject: | [Snort-users] rules Vs. meta-rules |
| From: | "(infor) urko zurutuza" <uzurutuza@eps.mondragon.edu> |
| Date: | Thu, 29 Mar 2007 23:48:40 +0200 |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | snort-list@securepoint.com |
| List-archive: | <http://sourceforge.net/mailarchive/forum.php?forum=snort-users> |
| List-help: | <mailto:snort-users-request@lists.sourceforge.net?subject=help> |
| List-id: | "Snort users talk about... Snort!" <snort-users.lists.sourceforge.net> |
| List-post: | <mailto:snort-users@lists.sourceforge.net> |
| List-subscribe: | <https://lists.sourceforge.net/lists/listinfo/snort-users>, <mailto:snort-users-request@lists.sourceforge.net?subject=subscribe> |
| List-unsubscribe: | <https://lists.sourceforge.net/lists/listinfo/snort-users>, <mailto:snort-users-request@lists.sourceforge.net?subject=unsubscribe> |
| Sender: | snort-users-bounces@lists.sourceforge.net |
| Thread-index: | AcdyTAOdaxoqjsrkQE+MHkcQpxSYYw== |
| Thread-topic: | rules Vs. meta-rules |
Hi, Is there any way for creating some kind of meta-rules, where you could define that for example 2 or more snort rules would match a "meta-rule" and thus only trigger one (meta)alert? I think this could be quite interesting... URko ------------------------------------------------------------------------- Take Surveys. Earn Cash. Influence the Future of IT Join SourceForge.net's Techsay panel and you'll get the chance to share your opinions on IT & business topics through brief surveys-and earn cash http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Snort-users] Ignoring Alerts, Joel Esler |
|---|---|
| Next by Date: | Re: [Snort-users] rules Vs. meta-rules, Brian Caswell |
| Previous by Thread: | [Snort-users] Unifed login plugin, Carlos Terrón |
| Next by Thread: | Re: [Snort-users] rules Vs. meta-rules, Brian Caswell |
| Indexes: | [Date] [Thread] [Top] [All Lists] |