2006-02-04 08:15:42 -05:00
|
|
|
An up-to-date set of rules is needed for Snort to be useful as an IDS.
|
|
|
|
These can be downloaded manually or net/oinkmaster can be used to
|
|
|
|
download the latest rules from several different sources.
|
|
|
|
|
|
|
|
It is recommended that snort be run as an unprivileged chrooted user.
|
2006-10-10 09:33:17 -04:00
|
|
|
A _snort user/group and a log directory have been created for this
|
|
|
|
purpose. You should start snort with the following options to take
|
2006-02-04 08:15:42 -05:00
|
|
|
advantage of this:
|
2006-10-10 09:33:17 -04:00
|
|
|
|
|
|
|
-c /etc/snort/snort.conf -u _snort -g _snort -t /var/snort -l /var/snort/log
|