Snort mailing list archives
Alert only when n number of rule matches rcvd
From: "Jason Linden" <jlinden7 () adelphia net>
Date: Wed, 12 Feb 2003 16:22:44 -0500
I am trying to setup an rule that will only generate an alert if n number of packets are received in n number of seconds. IE like everyone else we receive a large number of false positive 'ICMP Destination Unreachable' alerts. I would like to configure snort to only generate an alert if say 30 of these packets are rcvd in 30 seconds. Is there any way to do this? Thanks! -jason
Current thread:
- Alert only when n number of rule matches rcvd Jason Linden (Feb 12)
- <Possible follow-ups>
- Alert only when n number of rule matches rcvd Jason Linden (Feb 13)
- Re: Alert only when n number of rule matches rcvd Erek Adams (Feb 13)