snort/snort.conf

Thu, 04 Oct 2012 20:30:05 +0200

author
Michael Schloh von Bennewitz <michael@schloh.com>
date
Thu, 04 Oct 2012 20:30:05 +0200
changeset 715
c10fb90893b9
permissions
-rw-r--r--

Correct out of date build configuration, porting to Solaris 11 network
link infrastructure and new libpcap logic. This additionally allows for
device drivers in subdirectories of /dev. Correct packaged nmap
personalities and signatures to work out of the box. Finally, hack
arpd logic to properly close sockets and quit on TERM by repeating
signaling in the run command script. Sadly, all this fails to correct
the run time behaviour of honeyd which fails to bind to the IP layer.

     1 ##
     2 ##  snort.conf -- Snort Daemon Configuration
     3 ##
     5 #   common variables
     6 var VAR_PATH  @l_prefix@/var/snort
     7 var RULE_PATH $VAR_PATH/rules
     9 #   output selection
    10 config alertfile:    $VAR_PATH/snort.alert.log
    11 output alert_fast:   $VAR_PATH/snort.alert.log
    12 #output log_tcpdump: $VAR_PATH/snort.alert.cap
    14 #   configuration parameters
    15 config show_year
    16 config order: alert pass log
    18 #   load snort rules configuration
    19 var HOME_NET      any
    20 var EXTERNAL_NET  any
    21 include $RULE_PATH/snort.conf

mercurial