Snort - the de facto standard for intrusion detection/prevention
next up previous
Next: 4.8 Why does the Up: 4 Rules and Alerts Previous: 4.6 What about all

4.7 What are all these ICMP files in subdirectories under /var/log/snort?

Most of them are likely destination unreachable and port unreachables that were detected by snort when a communications session attempt fails.