[Snort-users] Perfmonitor / BPF Question

Rob Sharp robertsharp at ...11827...
Wed Jan 16 10:03:58 EST 2008


I have a sensor deployed with a BPF file to filter out our network
vulnerability scanners to keep the noise down.  I notice when the scanner
makes  a sweep that the dropped packets increase quite a bit.

My question is does the perfmonitor count packets dropped by the BPF in the
stats it tracks?  That would explain the jumps in packet loss.

-- 
Robert Sharp
robertsharp at ...11827...
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20080116/c3aada18/attachment.html>


More information about the Snort-users mailing list