Snort Alerts

Hi,

Using latest version snort on Debian. When something is logged in /var/log/snort/alerts

Does that mean snort blocked that traffic or its just an alert.

Thanks
LVL 1
masdf123Asked:
Who is Participating?
 
gheistConnect With a Mentor Commented:
Unless you configured flexresp it is a plain alert.
0
 
prerakgConnect With a Mentor Commented:
It wiil show you all the alerts. All the alerts will include according to the rulebase that you have set. It will have alerts for every traffic that is being checked even for the blocked traffic.

So its just alerts.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.