Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Snort-users] perfmonitor and pmgraph |
|---|---|
| Date: | Tue, 26 Sep 2006 11:28:14 -0400 |
Thanks Andreas. I think my only choice is to upgrade to 2.6 and hope the problem goes away. In the mean time, I wound up writing a Perl script to "normalize" the drops% field so that I can at least generate graphs that mean something. But, I also run `kill -USR1 [pidofsnort]` every midnight and the packet loss statistics reported by snort to syslog are not even close to the "normalized" perfmonitor data. Looks like it's garbage all the way through. :-\ PaulM -----Original Message----- From: Andreas Östling [mailto:andreaso@it.su.se] Sent: Monday, September 25, 2006 8:18 AM To: Paul Melson Subject: Re: [Snort-users] perfmonitor and pmgraph On Wednesday 20 September 2006 18:39, Paul Melson wrote:
I'm trying to use pmgraph to analyze Snort 2.4 perfmonitor statistics. Specifically, I am trying to troubleshoot dropped packets on a moderately busy sensor. The problem I am having with the perfmonitor file is that there seem to be some crazy values in the field that, as I understand it, is the % of dropped packets:
Looks like a bug in the perfmonitor preprocessor, I know it has had a few problems like that before on some platforms. The best thing is probably to try the latest 2.6 version. /Andreas ------------------------------------------------------------------------- Take Surveys. Earn Cash. Influence the Future of IT Join SourceForge.net's Techsay panel and you'll get the chance to share your opinions on IT & business topics through brief surveys -- and earn cash http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-users] Schedule Change for the Virtual Snort Users Group Webcast, Mike Guiterman |
|---|---|
| Next by Date: | Re: [Snort-users] perfmonitor and pmgraph, Bamm Visscher |
| Previous by Thread: | Re: [Snort-users] perfmonitor and pmgraph, Bamm Visscher |
| Next by Thread: | [Snort-users] Problem with Oinkmaster, Alejandro |
| Indexes: | [Date] [Thread] [Top] [All Lists] |