next up previous contents
Next: Tunneling Protocol Support Up: Basic Output Previous: Protocol Statistics   Contents

Actions, Limits, and Verdicts

Action and verdict counts show what Snort did with the packets it analyzed. This information is only output in IDS mode (when snort is run with the -c <conf> option).

Limits arise due to real world constraints on processing time and available memory. These indicate potential actions that did not happen:

Verdicts are rendered by Snort on each packet:

Example:

===============================================================================
Action Stats:
     Alerts:            0 (  0.000%)
     Logged:            0 (  0.000%)
     Passed:            0 (  0.000%)
Limits:
      Match:            0
      Queue:            0
        Log:            0
      Event:            0
      Alert:            0
Verdicts:
      Allow:      3716022 (100.000%)
      Block:            0 (  0.000%)
    Replace:            0 (  0.000%)
  Whitelist:            0 (  0.000%)
  Blacklist:            0 (  0.000%)
     Ignore:            0 (  0.000%)
===============================================================================


next up previous contents
Next: Tunneling Protocol Support Up: Basic Output Previous: Protocol Statistics   Contents
Eugene Misnik 2013-05-08