next up previous contents
Next: Format Up: General Rule Options Previous: Example   Contents

classtype

The classtype keyword is used to categorize a rule as detecting an attack that is part of a more general type of attack class. Snort provides a default set of attack classes that are used by the default set of rules it provides. Defining classifications for rules provides a way to better organize the event data Snort produces.



Subsections

Eugene Misnik 2013-05-08