[Snort-users] No trace for corresponding alerts

Sheahan, Paul (PCLN-NW) Paul.Sheahan at ...2218...
Thu Oct 4 09:18:02 EDT 2001


I'm using Snort 1.8.1 B78 on Red Hat Linux 7.0. I use the latest version of
snort_stat.pl to generate reports for me every night at midnight. I then
have the report emailed to me automatically.

For every alert, there has ALWAYS been a corresponding trace in my trace
file. This allows me to lookup details on alerts when needed. Ever since
upgrading to Build 78 and the latest snort_stat (both upgraded around the
same time), maybe 10% of the time, I find no corresponding trace for a given
alert. Not sure if this is a bug in Build 78 or the latest snort_stat, but
there is a DEFINITE problem. This worked flawlessly in the past. Has anyone
else experienced this? 


Paul Sheahan
Manager of Information Security
paul.sheahan at ...2218...

More information about the Snort-users mailing list