[Snort-users] Pat-Mached counter in perfmonitor preprocessor

Jeremy Hewlett jh at ...1935...
Tue Oct 19 11:36:43 EDT 2004


On Tue, Oct 19, sekure wrote:
> I've noticed a few occasions where the Pat-Matched counter in the
> perfmon preprocessor logs above 100%.  Is this normal?

Reassembled packets can sometimes cause this to be over 100%. The
bytes pattern matched stat is based off of wire packet bytes. If
you're seeing 10Mbit/s wire speed and reassembling 3Mbit/s this could
make a total of 13Mbit pattern matched. Since the actual wire speed
was only 10Mbit and the statistic is calculated by taking 
bytes_pattern_matched/wire_speed_bytes which would be 13Mbit/10Mbit ==
130%

> What exactly does "%bytes pattern matched" mean?  

Says what percent of traffic is being pattern matched by Snort. So, if
there's traffic that is not being pattern matched this will effect the
percentage.





More information about the Snort-users mailing list