Snort - the de facto standard for intrusion detection/prevention
next up previous contents
Next: Rule Keyword Format Up: Event Thresholding Previous: Standalone Format   Contents

Rule Keyword Format

This format supports 4 threshold options as described in Table [*]--all are required.


Table: Rule Keyword Options
Option Arguments
type limit, threshold, or both
track by_src or by_dst
count $<$number of events$>$
seconds $<$time period over which count is accrued$>$



Steven Sturges 2006-12-08