ok the problem is that when I setup threshold on
sfportsacn with
threshold gen_id 122, sig_id 1, type threshold, track
by_src, count 2, seconds 60
snort block all alerts from gen 122 sid 1 and don't output.
using snort-2.4.1
Nobody/Anonymous
None
None
Public
|
Date: 2007-04-04 03:48
|
|
Date: 2005-11-25 19:33 Logged In: NO |