[Snort-sigs] Tagged Packet?

Jason security at ...704...
Mon Jul 26 13:06:16 EDT 2004


The tagged packets are related to an alert that was previously raised. 
IIRC the event id should be the same for the tagged packets as the 
initial alert. These tagged packets should contain the information 
needed to figure out if this is an attack that you care about.

what tool are you using for analysis?


Rowland, Krisa W ERDC-ITL-MS Contractor wrote:

>  
> I am getting a large number of alerts for Tagged Packets?  There is no Snort
> sid and I looked through my bleeding.rules and didn't see it there either.
> Any ideas?
> 





More information about the Snort-sigs mailing list