This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

Setting up Snort on LEM

i have SNORT running on LEM 6.3.1 and it appears to be working as expected.... now what.  do i need to setup all of the alerts manually?  how does it know to alert me?  are there a set of best practice rules/alerts?