perf_test.sh
"Li, Charlie via Snort-users" <[email protected]> Thu, 15 Feb 2024 23:09:19 +0000
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <CY5PR12MB652588252A7EDA2992C217248E4D2@CY5PR12MB6525.namprd12.prod.outlook.com> |
[AMD Official Use Only - General]
Hi All,
I am running perf_test.sh to measure Snort3 performance against the community rules.
It runs the following configs:
* Decode
* Stream
* Inspect
* Detect-Min
* Detect-Max
* Network-Awareness
The README doc gives the following definitions of the above configs.
1. decode.{conf,lua} - just decode packets. No inspectors or rules.
2. stream.{conf,lua} - adds stream only to decode conf. No non-stream inspectors. No rules.
3. inspect.{conf,lua} - full configuration w/o rules.
4. detect-min.{conf,lua} - adds rules to snort.conf.
5. detect-max.{conf,lua} - same as min except with unlimited http flow depths.
It does not define “Network-Awareness” – what does it mean?
For “inspect”, what does “full configuration” mean?
Regards,
Charlie Li
_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users
To unsubscribe, send an email to:
[email protected]
Please visit http://blog.snort.org to stay current on all the latest Snort news!
Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette