編輯snort.conf
snort.conf位置在 [作業系統槽]\snort\etc\ 裡面
找尋var RULE_PATH ../ rules 改為var RULE_PATH [作業系統槽]:\snort\rules
找尋# output database: log, mysql, user=root password=test dbname=db host=localhost
改為output database: alert, mysql, user=snort password=[mySQL密碼] dbname=snort_log host=localhost sensor_name=[本機電腦名稱]
(均為同一行)
找尋include classification.config 改為include [作業系統槽]:\snort\etc\classification.config
找尋include reference.config 改為include [作業系統槽]:\snort\etc\reference.config
找尋dynamicpreprocessor directory /usr/local/lib/snort_dynamicpreprocessor/ 改為
dynamicpreprocessor directory [作業系統槽]:\Snort\lib\snort_dynamicpreprocessor
找尋# output log_tcpdump: tcpdump.log (請全部鍵入搜尋工具尋找,有相當相似的另一選項)
改為output alert_fast: alert.ids