Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Snort Advanced » tag anomaly

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

tag anomaly


Posted by slighter on March 14, 2005 07:55:05

Have been using the "tag" feature for many alerts that need to collect data in order to replay the session. The peculiar behavior is when using tag: session, 3, seconds for a single alert, there are times when the behavior is exactly as anticipated. However, there are times when several thousand "tagged" packets flood the console that are not even related to the alert. Is it possible that the "tag" behavior can be impacted by the order in which it is placed in the alert rule? How and when does one make a determination if the isset and isnotset options should be used with "tag" ?