Snort mailing list archives

Question About Threshholds


From: Miso Patel <miso.patel () gmail com>
Date: Wed, 20 Mar 2013 10:40:10 -0500

I apologize for a simple question but I was hoping for some clarity on a
situation from my engineers.

If a Snort signature is threshold (using the "limit" option), does this
just limit alerts and does the dropping of this traffic if this rule is
written to drop and the Snort is in "IPS mode" still happen even if the
threshold is causing not all alerts to be generated?

I think it does  but the Snort manual does not make this clear or I am not
reading the right pages.

Thanks.

-Miso, CISO
------------------------------------------------------------------------------
Everyone hates slow websites. So do we.
Make your web apps faster with AppDynamics
Download AppDynamics Lite for free today:
http://p.sf.net/sfu/appdyn_d2d_mar
_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists sourceforge net
https://lists.sourceforge.net/lists/listinfo/snort-sigs
http://www.snort.org


Please visit http://blog.snort.org for the latest news about Snort!

Current thread: