Snort mailing list archives

Alert only when n number of rule matches rcvd


From: "Jason Linden" <jlinden7 () adelphia net>
Date: Wed, 12 Feb 2003 16:22:44 -0500

I am trying to setup an rule that will only generate an alert if n
number of packets are received in n number of seconds.  IE like everyone
else we receive a large number of false positive 'ICMP Destination
Unreachable' alerts.  I would like to configure snort to only generate
an alert if say 30 of these packets are rcvd in 30 seconds.  Is there
any way to do this?
 
Thanks!
 
-jason
 

Current thread: