Re: Snort Timestamps Out of Sequence
"Joel Esler \(jesler\) via Snort-devel" <[email protected]> Mon, 6 May 2019 13:44:04 +0000
| Newsgroups | gmane.comp.security.ids.snort.devel |
|---|---|
| Message-ID | <[email protected]> |
Hey Alan, My "off the cuff" theory, without looking at your Snort configuration and requesting a full traffic reassembly is that something was holding the connection open (for 7 minutes) (keep-alive?) and Snort is reassembling the HTTP session in the background into what we call a "pseudo" packet. A large reassembled stream. That's what your rule alerted on, and should have logged it to disk. -- Joel Esler Manager, Communities Division Cisco Talos Intelligence Group http://www.talosintelligence.com On May 6, 2019, at 9:16 AM, ROTNEMER, ALAN H <[email protected]<mailto:[email protected]>> wrote: Is there some explanation as to why the alert took over 7 minutes to publish? Could Snort be waiting on anything in order to complete the alert? _______________________________________________ Snort-devel mailing list [email protected] https://lists.snort.org/mailman/listinfo/snort-devel Please visit http://blog.snort.org for the latest news about Snort!