[Snort-users] Tagged Packet

Esler, Joel - Contractor joel.esler at ...9426...
Tue Sep 28 12:21:34 EDT 2004


tagged packets... look for a rule with the keyword "tag:" in it.
usually tagged sessions are important.  tagged sessions are especially
helpful if you are logging in binary mode, you can reconstruct the
session.
 
J

-----Original Message-----
From: snort-users-admin at lists.sourceforge.net
[mailto:snort-users-admin at lists.sourceforge.net] On Behalf Of Rowland,
Krisa W ERDC-ITL-MS Contractor
Sent: Tuesday, September 28, 2004 11:45 AM
To: 'snort-users at lists.sourceforge.net'
Subject: [Snort-users] Tagged Packet



I am suddenly getting all these Tagged Packet alerts.  Seems like I
turned this off before - can someone remind me how to do this?


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20040928/2be7235a/attachment.html>


More information about the Snort-users mailing list