Use Snort as Instrusion Detection only not Prevention
Is it possible to use Snort as Instrusion Detection only not Prevention? I need to monitor it for a while before setting it in production.
I have installed the latest Snort package, but I do not see any option in the General settings tab or elsewhere.
Have you loaded any rules?
No, not yet. I just installed it.
Do I have to load the rules and assign interface first?
Doesn't matter. If you download the rules first you can setup the interface in a single sweep (don't forget to enable at least the HTTP Inspect preproc or most rules won't work).
Thank you. And how can I see what is blocked (or detected)?
Services: Snort: Snort Alerts
Services: Snort Blocked Hosts