|
|
|
|
Snort Forums Archive
Archive Home » Snort Advanced » tag anomaly
Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.
[ Notice: Full Version of This Topic ]
tag anomaly
Posted by slighter on March 14, 2005 07:55:05
Have been using the "tag" feature for many alerts that need to collect data in order to replay the session. The peculiar behavior is when using tag: session, 3, seconds for a single alert, there are times when the behavior is exactly as anticipated. However, there are times when several thousand "tagged" packets flood the console that are not even related to the alert. Is it possible that the "tag" behavior can be impacted by the order in which it is placed in the alert rule? How and when does one make a determination if the isset and isnotset options should be used with "tag" ?
|
|
|
|
|
|