IDS ensure a security policy in every single packet passing through the network.
Snort is an open-source , lightweight tool which captures every detail of packet passing through the network and generate alerts if any one packets matches the signatures inserted given by the company.
An IDS is designed to only provide an alert about a potential incident, which enables a security operations center (SOC) analyst to investigate the event and determine whether it requires further action.
An IPS, on the other hand, takes action itself to block the attempted intrusion or otherwise remediate the incident.
Yes.
Snort is a "network packet sniffer" that inspects network traffic and carefully examines each packet to find any suspicious irregularities or potentially harmful payloads.