Log directory = /var/log/snort TCPDUMP file reading mode. Reading network traffic from "snort-0718@1401.log" file. snaplen = 1514 --== Initializing Snort ==-- Initializing Preprocessors! Initializing Plug-ins! Initializating Output Plugins! Parsing Rules file /etc/snort/snort.conf +++++++++++++++++++++++++++++++++++++++++++++++++++ Initializing rule chains... No arguments to frag2 directive, setting defaults to: Fragment timeout: 60 seconds Fragment memory cap: 4194304 bytes Stream4 config: Stateful inspection: ACTIVE Session statistics: INACTIVE Session timeout: 30 seconds Session memory cap: 8388608 bytes State alerts: INACTIVE Scan alerts: ACTIVE Log Flushed Streams: INACTIVE No arguments to stream4_reassemble, setting defaults: Reassemble client: ACTIVE Reassemble server: INACTIVE Reassemble ports: 21 23 25 53 80 143 110 111 513 Reassembly alerts: ACTIVE Reassembly method: FAVOR_OLD Back Orifice detection brute force: DISABLED Using LOCAL time 1228 Snort rules read... 1228 Option Chains linked into 146 Chain Headers 0 Dynamic rules +++++++++++++++++++++++++++++++++++++++++++++++++++ Rule application order: ->activation->dynamic->alert->pass->log --== Initialization Complete ==-- -*> Snort! <*- Version 1.8.4-beta1 (Build 91) By Martin Roesch (roesch@sourcefire.com, www.snort.org) =============================================================================== Snort processed 5085 packets. Breakdown by protocol: Action Stats: TCP: 4812 (94.631%) ALERTS: 20 UDP: 229 (4.503%) LOGGED: 20 ICMP: 18 (0.354%) PASSED: 0 ARP: 0 (0.000%) IPv6: 0 (0.000%) IPX: 0 (0.000%) OTHER: 26 (0.511%) =============================================================================== Fragmentation Stats: Fragmented IP Packets: 0 (0.000%) Rebuilt IP Packets: 0 Frag elements used: 0 Discarded(incomplete): 0 Discarded(timeout): 0 =============================================================================== TCP Stream Reassembly Stats: TCP Packets Used: 4256 (83.697%) Reconstructed Packets: 100 (1.967%) Streams Reconstructed: 867 ===============================================================================