next up previous contents
Next: Packet Acquisition Up: Network Intrusion Detection System Previous: High Performance Configuration   Contents

Changing Alert Order

The default way in which Snort applies its rules to packets may not be appropriate for all installations. The Pass rules are applied first, then the Drop rules, then the Alert rules and finally, Log rules are applied.

Note:   Sometimes an errant pass rule could cause alerts to not show up, in which case you can change the default ordering to allow Alert rules to be applied before Pass rules. For more information, please refer to the -alert-before-pass option.

Several command line options are available to change the order in which rule actions are taken.

Note:  

Pass rules are special cases here, in that the event processing is terminated when a pass rule is encountered, regardless of the use of -process-all-events.


next up previous contents
Next: Packet Acquisition Up: Network Intrusion Detection System Previous: High Performance Configuration   Contents
Eugene Misnik 2013-05-08