Re: [LOGS] Summary of large-scale portscanning detects
Ken Connelly <[email protected]> Thu, 17 Mar 2005 06:18:57 -0600
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
Mark Stingley wrote: > [email protected] wrote: > >> This will be the last of these postings for some unknown interval. >> As of >> today, I am moving on to a newer version of my IDS that logs scans >> differently. Dilbert says, "Change is good. You go first." Well, it >> seems like it's my turn to go... When I figure out how to easily >> automate >> a similar report from the new format, these may return. Until then, >> it's >> been nice... - ken > > > If you send me a some output, I'd be more than > happy to help out. > In a nutshell, I'm now looking at the output of sfportscan in snort 2.3.1, which logs summaries instead of detail lines. -- - Ken ================================================================= Ken Connelly Systems and Operations Manager, ITS Network Services University of Northern Iowa Cedar Falls, IA 50614-0121 email: [email protected] phone: (319) 273-5850 fax: (319) 273-7373 It's much more important to know what you don't know than what you do know! _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions