Snort mailing list archives

Re: Pat-Mached counter in perfmonitor preprocessor


From: sekure <sekure () gmail com>
Date: Tue, 19 Oct 2004 15:09:04 -0400

On Tue, 19 Oct 2004 14:27:14 -0400, Jeremy Hewlett <jh () sourcefire com> wrote:
On Tue, Oct 19, sekure wrote:
I've noticed a few occasions where the Pat-Matched counter in the
perfmon preprocessor logs above 100%.  Is this normal?

Reassembled packets can sometimes cause this to be over 100%. 

Makes sense.  

What exactly does "%bytes pattern matched" mean?

Says what percent of traffic is being pattern matched by Snort. So, if
there's traffic that is not being pattern matched this will effect the
percentage.

Can you explain why certain traffic wouldn't be pattern matched? 
Matched against what pattern? The signatures? I am seeing < 70%
pattern matched on some sensors.  Is this "bad"?


-------------------------------------------------------
This SF.net email is sponsored by: IT Product Guide on ITManagersJournal
Use IT products in your business? Tell us what you think of them. Give us
Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more
http://productguide.itmanagersjournal.com/guidepromo.tmpl
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: