Re: Strange Alerts
Jim Campbell via Snort-users <[email protected]> Wed, 31 May 2023 18:59:43 -0400
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
I appreciate the prompt responses to my questions. I do have the ability to capture the packets in question but before I do that I have another question. Are these packets something to be concerned about? If so, I will get WireShark involved. If not, how do I tell Snort to ignore them? Thank you, Jim Campbell On 5/31/2023 4:47 PM, Al Lewis (allewi) wrote: > Look like IGMP traffic > > https://www.iana.org/assignments/multicast-addresses/multicast-addresses.xhtml > > > *Albert Lewis* > > ENGINEER.SOFTWARE ENGINEERING > > SOURCE*fire*, Inc. now part of *Cisco* > > Email: [email protected] <mailto:[email protected]> > > ------------------------------------------------------------------------ > *From:* Al Lewis (allewi) <[email protected]> > *Sent:* Wednesday, May 31, 2023 4:45 PM > *To:* Snort-users <[email protected]>; Jim Campbell > <[email protected]> > *Subject:* Re: [Snort-users] Strange Alerts > Have you been able to look at the packets? Which options are set in > the header? > > *Albert Lewis* > > ENGINEER.SOFTWARE ENGINEERING > > SOURCE*fire*, Inc. now part of *Cisco* > > Email: [email protected] <mailto:[email protected]> > > ------------------------------------------------------------------------ > _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette