Snort
[Top] [All Lists]

Re: [Snort-users] Looooots of "Outstanding" and "Analyzed" packets - cou

To: Bamm Visscher <bamm.visscher@gmail.com>
Subject: Re: [Snort-users] Looooots of "Outstanding" and "Analyzed" packets - counter wrap ?
From: Andreas Maus <maus@ypbind.de>
Date: Mon, 27 Nov 2006 16:19:15 +0100
Cc: snort-users@lists.sourceforge.net
Delivered-to: sp-com-lists@consult.net
Delivered-to: snort-list@securepoint.com
In-reply-to: <27492850611270657s11493728v6521b577332f13df@mail.gmail.com>
List-archive: <http://sourceforge.net/mailarchive/forum.php?forum=snort-users>
List-help: <mailto:snort-users-request@lists.sourceforge.net?subject=help>
List-id: "Snort users talk about... Snort!" <snort-users.lists.sourceforge.net>
List-post: <mailto:snort-users@lists.sourceforge.net>
List-subscribe: <https://lists.sourceforge.net/lists/listinfo/snort-users>, <mailto:snort-users-request@lists.sourceforge.net?subject=subscribe>
List-unsubscribe: <https://lists.sourceforge.net/lists/listinfo/snort-users>, <mailto:snort-users-request@lists.sourceforge.net?subject=unsubscribe>
References: <20061122185558.GF9692@debian3164m> <27492850611260843r3f76e352y10a2656625cfc26a@mail.gmail.com> <20061127093045.GA10259@debian3164m> <27492850611270657s11493728v6521b577332f13df@mail.gmail.com>
Sender: snort-users-bounces@lists.sourceforge.net
User-agent: mutt-ng/devel-r804 (Linux)
On Mon, Nov 27, 2006 at 07:57:04AM -0700, Bamm Visscher wrote:
> 
> Do try a newer version, there are known statisic issues with Linux and
> older versions of libpcap.
> 
> Bammkkkk
Thanks.
Building libpcap 0.9.5 and linking against snort did the trick:

*** Caught Usr-Signal
Snort ran for 0 Days 5 Hours 21 Minutes 46 Seconds
Packet analysis time averages:

Snort Analyzed 3520 Packets Per Hour
Snort Analyzed 54 Packets Per Minute
Snort Analyzed 0 Packets Per Second

Snort received 17604 packets
    Analyzed: 17603(99.994%)
    Dropped: 0(0.000%)
    Outstanding: 1(0.006%)
===============================================================================
Breakdown by protocol:
    TCP: 13131      (74.595%)
    UDP: 573        (3.255%)
   ICMP: 84         (0.477%)
    ARP: 3815       (21.672%)
  EAPOL: 0          (0.000%)
   IPv6: 0          (0.000%)
ETHLOOP: 0          (0.000%)
    IPX: 0          (0.000%)
   FRAG: 0          (0.000%)
  OTHER: 0          (0.000%)
DISCARD: 0          (0.000%)
===============================================================================
Action Stats:
ALERTS: 31
LOGGED: 31
PASSED: 0
===============================================================================
TCP Stream Reassembly Stats:
    TCP Packets Used: 13131      (74.595%)
    Stream Trackers: 575
    Stream flushes: 22
    Segments used: 41
    Segments Queued: 42
    Stream4 Memory Faults: 0
===============================================================================

Many thanks,

Andreas.


-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys - and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

<Prev in Thread] Current Thread [Next in Thread>