next up previous contents
Next: Investigations Up: Analysis Previous: Services   Contents

Missing Snort Alerts

There is still one issue we have not resolved. Why are there about 324461 log entries, but for about 70,000 of them we were not able to generate a snort alert. Out of these 70,000 events, more than 69.000 are related to Web traffic (targeting or originating from port 80).

There are multiple possible reasons for this:



Raffy 2004-12-20