HI
Deleted everything in the log folder.
Home_net is set as such :
# Setup the network addresses you are protecting
ipvar HOME_NET any
# Set up the external network addresses. Leave as "any" in most situations
ipvar EXTERNAL_NET any
I’m trying to check the config on our Cisco 3750 but I’m sure port mirroring is working ok.
Rebooted snort server and it just sits there waiting for new data.
*** Seeing as it logs traffic when using the test rule does that mean it is capturing data fine, So this tells me that one of the other rules is blocking the data capture ??
black_list.rules, deleted.rules, experimental.rules, local.rules, white_list.rules, winids.rules
Thanks, Gary