Re: snort3 profiling
"Steven Baigal \(sbaigal\) via Snort-users" <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <BL0PR11MB28985D6098C605914D893AC6B36D9@BL0PR11MB2898.namprd11.prod.outlook.com> |
Use profiler, for example:
Profiler = { }
or
profiler = { rules = { show = true, sort = 'total_time', count = 25 }}
see help for details:
snort --help-config profiler
From: Snort-users <[email protected]> on behalf of Mohammad Hachem <[email protected]>
Date: Monday, December 6, 2021 at 1:35 PM
To: [email protected] <[email protected]>
Subject: [Snort-users] snort3 profiling
Hi,
Is profiling supported on snort3 , if so what is the correct syntax.
I tried to add the below to my snort.lua configuration file but I am getting a syntax error when trying to load the configuration
config profile_rules: print 100, sort total_ticks, filename /tmp/rules_out
config profile_preprocs: print 10, sort total_ticks, filename /tmp/preproc_out
Regards,
Mohammad Hachem
_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users
To unsubscribe, send an email to:
[email protected]
Please visit http://blog.snort.org to stay current on all the latest Snort news!
Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette