Snort mailing list archives

Re: Critical Path value


From: waldo kitty <wkitty42 () windstream net>
Date: Tue, 20 Aug 2013 12:11:35 -0400

On 8/20/2013 00:45, waldo kitty wrote:
On 8/20/2013 00:18, Balasubramaniam Natarajan wrote:
It is the time taken to decode, detect and report the traffic which is
malicious.   I know that prefmon can do it for rules which are bad however I am
not too sure if it includes the CPU cycles for decoding the traffic as well.

cpu cycles? no... but microseconds are listed... for both preprocessors and
rules with the proper settings, of course ;)

argh! it was pretty late last night when i wrote that... i was thinking of the 
rules and preprocessor profiling which show microseconds or (clock) ticks... i 
haven't found anything at all that has any way of causing snort to determine CPU 
cycles used for anything... everything is measures in some portion of (clock) 
seconds...

-- 
NOTE: No off-list assistance is given without prior approval.
       Please keep mailing list traffic on the list unless
       private contact is specifically requested and granted.

------------------------------------------------------------------------------
Introducing Performance Central, a new site from SourceForge and 
AppDynamics. Performance Central is your source for news, insights, 
analysis and resources for efficient Application Performance Management. 
Visit us today!
http://pubads.g.doubleclick.net/gampad/clk?id=48897511&iu=/4140/ostg.clktrk
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: