Snort mailing list archives

parameter problem


From: "李敏" <fly.limin () gmail com>
Date: Fri, 14 Nov 2008 15:19:51 +0800

when I use the command snort -dev -n 1,it shows like this:
===============================================================================

Snort received 7 packets
    Analyzed: 7(100.000%)
    Dropped: 0(0.000%)
===============================================================================
Breakdown by protocol:
    TCP: 1          (14.286%)
    UDP: 0          (0.000%)
   ICMP: 0          (0.000%)
    ARP: 0          (0.000%)
  EAPOL: 0          (0.000%)
   IPv6: 0          (0.000%)
    IPX: 0          (0.000%)
  OTHER: 0          (0.000%)
DISCARD: 0          (0.000%)
===============================================================================

according to the "man snort" ,we can set "-n" to decide how many packets to
process, but it shows snort received 7 packets and analyzed 7,not 1.
since I know it is relative to the pkt_cnt parameter in the source code, but
what it really means?
-- 
Min Li
School of Computer Science and Technology
Cluster and Grid Computing Lab
Services Computing Technology and System Lab
Huazhong University of Science and Technology
Wuhan, 430074, China
Tel: 13986251431 027-65236831
Email: fly.limin () gmail com
-------------------------------------------------------------------------
This SF.Net email is sponsored by the Moblin Your Move Developer's challenge
Build the coolest Linux based applications with Moblin SDK & win great prizes
Grand prize is a trip for two to an Open Source event anywhere in the world
http://moblin-contest.org/redirect.php?banner_id=100&url=/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Current thread: