i have SNORT running on LEM 6.3.1 and it appears to be working as expected.... now what. do i need to setup all of the alerts manually? how does it know to alert me? are there a set of best practice rules/alerts?
↧
i have SNORT running on LEM 6.3.1 and it appears to be working as expected.... now what. do i need to setup all of the alerts manually? how does it know to alert me? are there a set of best practice rules/alerts?