Snort mailing list archives
Re: Pat-Mached counter in perfmonitor preprocessor
From: Jeremy Hewlett <jh () sourcefire com>
Date: Tue, 19 Oct 2004 14:27:14 -0400
On Tue, Oct 19, sekure wrote:
I've noticed a few occasions where the Pat-Matched counter in the perfmon preprocessor logs above 100%. Is this normal?
Reassembled packets can sometimes cause this to be over 100%. The bytes pattern matched stat is based off of wire packet bytes. If you're seeing 10Mbit/s wire speed and reassembling 3Mbit/s this could make a total of 13Mbit pattern matched. Since the actual wire speed was only 10Mbit and the statistic is calculated by taking bytes_pattern_matched/wire_speed_bytes which would be 13Mbit/10Mbit == 130%
What exactly does "%bytes pattern matched" mean?
Says what percent of traffic is being pattern matched by Snort. So, if there's traffic that is not being pattern matched this will effect the percentage. ------------------------------------------------------- This SF.net email is sponsored by: IT Product Guide on ITManagersJournal Use IT products in your business? Tell us what you think of them. Give us Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more http://productguide.itmanagersjournal.com/guidepromo.tmpl _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Pat-Mached counter in perfmonitor preprocessor sekure (Oct 19)
- Re: Pat-Mached counter in perfmonitor preprocessor Jeremy Hewlett (Oct 19)
- Re: Pat-Mached counter in perfmonitor preprocessor sekure (Oct 19)
- Re: Pat-Mached counter in perfmonitor preprocessor Jeremy Hewlett (Oct 19)
- Re: Pat-Mached counter in perfmonitor preprocessor sekure (Oct 19)
- Re: Pat-Mached counter in perfmonitor preprocessor Jeremy Hewlett (Oct 19)