im not sure but i think this might change things:
NOTE: Snort's default output has changed in version 2.4.1! The default logging mode is now PCAP, use "-K ascii" to activate the old default logging mode. |
No it doesn't.
|
im not kidding! really; this is part of what comes up every time i run 'snort -ve' (and i have the latest version of snort too). i swear, not trying to pull your leg/ steal your cheese/ pull the wool over your eyes/ blaspheme the penguin.
|
Look for it under the header "Snort unified format alerting and logging", else post your new snort.conf.
|
All times are GMT -5. The time now is 04:08 PM. |