[Snort-users] Noob Rules Question

Turnbough, Bradley E. bturnbough at ...15650...
Thu Oct 18 12:39:20 EDT 2012

I just spun up Snort and Barnyard2.  Everything is working fine, except that roughly 90% of my alerts getting inserted into the DB are "stream 5 TCP Timestamp is missing"

Is this a rule that needs to be tweaked, or should it be disabled altogether?


This e-mail transmission contains information that is confidential and may be privileged. It is intended only for the addressee(s) named above. If you receive this e-mail in error, please do not read, copy or disseminate it in any manner. If you are not the intended recipient, any disclosure, copying, distribution or use of the contents of this information is prohibited. Please reply to the message immediately by informing the sender that the message was misdirected. After replying, please erase it from your computer system. Your assistance in correcting this error is appreciated.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20121018/46c7e802/attachment.html>

More information about the Snort-users mailing list