Snort mailing list archives
Pat-Mached counter in perfmonitor preprocessor
From: sekure <sekure () gmail com>
Date: Tue, 19 Oct 2004 12:04:26 -0400
Snort -2.2.0 on Linux 2.4.21 preprocessor perfmonitor: time 300 flow events file snort.stats pktcnt 10000 I've noticed a few occasions where the Pat-Matched counter in the perfmon preprocessor logs above 100%. Is this normal? What exactly does "%bytes pattern matched" mean? Percent of bytes captured that matched a rule? That doesn't make sense, since i'd expect it to be something like .01%. Percent of bytes captured that got tested against a various signatures? Why wouldn't it always be 100%? In other words: Help??? ------------------------------------------------------- This SF.net email is sponsored by: IT Product Guide on ITManagersJournal Use IT products in your business? Tell us what you think of them. Give us Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more http://productguide.itmanagersjournal.com/guidepromo.tmpl _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Pat-Mached counter in perfmonitor preprocessor sekure (Oct 19)
- Re: Pat-Mached counter in perfmonitor preprocessor Jeremy Hewlett (Oct 19)
- Re: Pat-Mached counter in perfmonitor preprocessor sekure (Oct 19)
- Re: Pat-Mached counter in perfmonitor preprocessor Jeremy Hewlett (Oct 19)
- Re: Pat-Mached counter in perfmonitor preprocessor sekure (Oct 19)
- Re: Pat-Mached counter in perfmonitor preprocessor Jeremy Hewlett (Oct 19)