| Search Site |
| Search Rules |
| Account |
| not registered? |
| can't login? |
| user preferences |
|
|||||||||||||||||||||||
|
Next: Preprocessor Profiling Up: Rule Profiling Previous: Examples Contents OutputSnort will print a table much like the following at exit. Configuration line used to print the above table: config profile_rules: print 4, sort total_ticks The columns represent:
Interpreting this info is the key. The Microsecs (or Ticks) column is important because that is the total time spent evaluating a given rule. But, if that rule is causing alerts, it makes sense to leave it alone.
A high Avg/Check is a poor performing rule, that most likely contains PCRE.
High Checks and low Avg/Check is usually an any-
Next: Preprocessor Profiling Up: Rule Profiling Previous: Examples Contents Steven Sturges 2008-04-01 |
|||||||||||||||||||||||
|
|||||||||||||||||||||||