So there was some discussion some time back about having
snort report multiple ICMP and related type alerts once
rather than the alert being generated by each packet.  Did
anything come of that?

The reason I ask (other than wanting to see that feature
myself) is that it occurred to me that the portscan preprocessor
plugin thingy already has that functionality.  That plugin already
tracks certain types of traffic coming from a single host to many hosts
and reports the duration and rate of the scan.  How reusable is
that code (for ICMP DDoS alerts)?

Or perhaps this was all resolved while I was away... comments?


