|
|
|
|
Snort Forums Archive
Archive Home » Snort Advanced » ssp_portscan events missing src & dst information
Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.
[ Notice: Full Version of This Topic ]
ssp_portscan events missing src & dst information
Posted by grass_sniffer on July 15, 2005 07:56:57
My SNORT sensor is capturing many events titled:
"ssp_portscan: End of portscan from x.x.x.x ..."
Problem:
Detailed info is missing
Protocol
Src IP
Src Port
Dst IP
Dst Port
Does any one have an idea why this is happening? What can I do to tune the sensor to stop capturing this noise? Is it just noise or is it legitimate? |
|
Posted by Joel_Esler on August 30, 2005 10:44:42
This is your portscan preprocessor detecting possible portscans. Please see the portscan documentation
for assistance on how to tune these out.
Joel Esler
SOURCEfire |
|
|
|
|
|