Monitoring and Dealing With Snort Alerts

Posted by tuxchick on Oct 13, 2011 2:38 AM EDT
Olex Wazi; By Juliet Kemp
Mail this story
Print this story

Snort, the open source intrusion detection and prevention system, is immensely powerful, but to get the most out of it, you need to configure it correctly for your own setup. Here are some performance tips for dealing well with alerts, looking at alert monitoring, streamlining false positives and genuine but frequent real positives, and logical rule optimization.

Full Story

  Nav
» Read more about: Story Type: Tutorial; Groups: Community, Linux

« Return to the newswire homepage

This topic does not have any threads posted yet!

You cannot post until you login.