I've been playing with Snort on and off for a while now. Just setup the Snort_Panel interface and am curious if anyone has done this?
I've setup test rules like this:
alert tcp any any -> 192.168.1.0/24 135
alert tcp any any -> 192.168.1.0/24 80
alert tcp any any -> 192.168.1.0/24 137
alert tcp any any -> 192.168.1.0/24 5000
tho when I port scan the machine, nothing appears in the snort logs. I've set the log directory to c:/snort/log and told Snort_Panel this location. The Alert.IDS file remains blank tho.
Any ideas?
I've setup test rules like this:
alert tcp any any -> 192.168.1.0/24 135
alert tcp any any -> 192.168.1.0/24 80
alert tcp any any -> 192.168.1.0/24 137
alert tcp any any -> 192.168.1.0/24 5000
tho when I port scan the machine, nothing appears in the snort logs. I've set the log directory to c:/snort/log and told Snort_Panel this location. The Alert.IDS file remains blank tho.
Any ideas?