Snort mailing list archives
Question About Threshholds
From: Miso Patel <miso.patel () gmail com>
Date: Wed, 20 Mar 2013 10:40:10 -0500
I apologize for a simple question but I was hoping for some clarity on a situation from my engineers. If a Snort signature is threshold (using the "limit" option), does this just limit alerts and does the dropping of this traffic if this rule is written to drop and the Snort is in "IPS mode" still happen even if the threshold is causing not all alerts to be generated? I think it does but the Snort manual does not make this clear or I am not reading the right pages. Thanks. -Miso, CISO
------------------------------------------------------------------------------ Everyone hates slow websites. So do we. Make your web apps faster with AppDynamics Download AppDynamics Lite for free today: http://p.sf.net/sfu/appdyn_d2d_mar
_______________________________________________ Snort-sigs mailing list Snort-sigs () lists sourceforge net https://lists.sourceforge.net/lists/listinfo/snort-sigs http://www.snort.org Please visit http://blog.snort.org for the latest news about Snort!
Current thread:
- Question About Threshholds Miso Patel (Mar 20)
- Re: Question About Threshholds Alex Kirk (Mar 20)