Snort 2.1.3 RC1 available

Jeremy Hewlett <[email protected]> Wed, 21 Apr 2004 18:14:42 -0400
Newsgroups gmane.comp.security.ids.snort.announce
Message-ID <[email protected]>
Hello all,

We're proud to release Snort 2.1.3 Release Candidate 1. We're
releasing this as a Release Candidate so the community can give us
feedback on what they like or dislike about the new method of logging
events. We'd also like to get any suggestions on other event ordering
algorithms that users would like to order events with. We currently
support ordering events based on Event Priority and Rule Content
Length.

The following is a list of the major changes in Snort 2.1.3 RC1:

* Added multi-event queueing in Snort.  Snort now supports logging
  multiple events per packet, and prioritizing those events using
  different methods.  Thanks to H.D. Moore for illustrating event
  obfuscations when snort only logged one event per packet.

  Please see ./doc/README.event_queue for details

* Fixed timezone problems with database output plugins. Thanks Marcus
  Janoski and Chris Reid.

* Revert to old tag functionality.  Will add proposed tagging
  configurations in a future release.

Thanks to everyone for supporting Snort development and giving us
your feedback!

Cheers,
The Snort Team


-------------------------------------------------------
This SF.net email is sponsored by: The Robotic Monkeys at ThinkGeek
For a limited time only, get FREE Ground shipping on all orders of $35
or more. Hurry up and shop folks, this offer expires April 30th!
http://www.thinkgeek.com/freeshipping/?cpg=12297