What to expect with the "log pair" actions

I've never quite understood what I should expect to find in the pcap file for the "log pair packets" action. Take the following example:
SigId: 6256-0 (HTTP Auth fail)
Engine: Atomic IP
TCP Mask: Ack,Fin,Rst,Syn
TCP Flags: Ack
Source Port Range: 80-80
Regex: [Hh][Tt][Tt][Pp][/][1][.][01][ \t][4][0][1]
Event Count: 25 <-not default
Event Count Key: Attacker and Victim Addresses
Alert Interval: 2 <-not default
What I would expect/hope to see is at least all 25 "atomic" packets which triggered the alarm. This doesn't seem to be the case however.
A string search through the pcap file (ethereal) for '401' finds only 5 hits...and all but one are separated by 5 or more seconds.
The very first packet in the pcap file matches the signature (i.e. it is a 401). Is the first packet in the pcap file the last packet that triggered the alarm?

In short, yes. Keep in mind logging is only started after the alert has fired, which in your case above would be AFTER we see the 25th packet in a 2sec period. Actually we will capture that 25th one as that is the TriggerPacket as you mentioned, plus whatever else occurs after that TriggerPacket, but we don't capture/log all 25 packets, simply because for the 1st to 24th packet the alert has not fired.

Similar Messages

  • What's wrong with the server?

    execute me ~what's wrong with the server? I can‘t use the command nohup any longer.Can somebody help me?
    root@shhis1new # nohup
    Segmentation Fault (core dumped)
    root@shhis1new # nohup ls
    Segmentation Fault (core dumped)
    root@shhis1new # nohup /opt/SUNWexplo/bin/explorer -w all &
    [1] 6871
    root@shhis1new #
    [1]+ Segmentation Fault (core dumped) nohup /opt/SUNWexplo/bin/explorer -w all
    root@shhis1new # uname -a
    SunOS shhis1new 5.9 Generic_122300-19 sun4u sparc SUNW,Netra-T12
    System Configuration: Sun Microsystems sun4u Sun Fire E2900
    System clock frequency: 150 MHZ
    Memory size: 49152 Megabytes
    Best Regards
    <email address removed by moderator>
    Edited by: 884082 on 2011-11-22 下午10:00

    Moderator Action:
    You email address has been removed from your post.
    You wouldn't want bad people to send you spam messages for the rest of your life, eh?
    Moderator Advice:
    If this is the same E2900 that you have mentioned in every one of your other forum posts, then it would seem you need to contact Technical Support and open a proper support request. These forums are NOT techsupport and that system seems so poorly configured that it needs deep analysis. Such investigation cannot be done by using an online forum.
    The immediate solution is to log on to the SC of that box and power it down, then boot it back up. At least it will be running after that.

  • What's up with the Iphone-5 ?

    What's up with the Iphone-5 that my wife and I just purchased? Neither one is now connecting to my WiFi Network.  All other devices in my home network work fine, including my old Droidx.  Did we just make a mistake by switching to the Iphone 5?

    I never said the devices are used concurrently.  I imagine that if they were there would be a limit.  What is being pointed out is that devices of various types, such as PSs of various manufacturers, I-Pods, I-pads, laptops of various manufacturers, gaming devices,  etc., when family comes to visit, have no issue logging in to my home Wi-Fi.  While I love Apple devices, why is it that when I buy the best and the latest I have an issue. In the end it turns out that the solution is quite simple, "before connecting to the home network, update the router software".  If this caution is there, I missed it and telling folks to re-initialize the router simply will not do it because, as was explained to me, the I-phone 5 is not compatible with "Security Encryption:WEN".  I am not a computer wiz, therefore I cannot tell you if that statement is correct, but telling people to re-boot the router will not work in this instance.

  • Does anyone know what's up with the iPhone 4s' battery life? Some days it last a long time and other days it drains extremely fast.

    Does anyone know what's up with the iPhone 4s' battery life? Some days it last a long time and other days it drains extremely fast.

    Not to point out the obvious, but battery life depends very much on what is running and how much the device is being used.
    If the battery lasts longer on a day you make no phone calls, but lasts less the day you make 5 hour long calls, this is to be expected.
    If however the iPhone has the same level of use on both days, with different power consumption, this would infer a background process (or App) is trying to do something (connecting to server or creating a back up etc).
    I switched off all thrid party apps from being included in my iCloud backup, which saves a huge amount of space on the cloud and allows the back up to take barely a couple of minutes.
    Battery life seems ok so far on my 64GB 4S (Bluetooth on, Wi-Fi on, Location Services on, Push notifications on, Screen set to just under half brightness with Auto Adjust on)

  • I have no idea what to do with the payments for stuff I bought on iTunes.

    Ok I had a card from a rebate atatched to the account and it has just expired. Now itunes wants me to pay from a different card for the things I bought in the week before it expired. I had the amount needed to pay for what i bought on the rebate card and bought my last thing before the card expired because i thought it would be stupid to let the money go without actually using it. I was looking today (it expired overnight) at itunes and now its saying i need to pay for them because the have not been pasyed for yet or something like that and i need to update the billing adress but i cant and dont want to one because i dont want to pay for something i had already had the money to pay for and they didnt charge me on it or something and 2 because i dont have another card to use bc i do not have a credit or checking or any card bc other than the rebate card i only have cash. sorry my question is so long but thank you for all the help you people can give me. ps i cant even get a card bc im 15

    The rebate card that my mom let me use was after they had bought a new phone and try had let me have what was left on it 7.92 and it counted as a visa credit card so I could use it to activate my account the problem is that I bought the stuff before it expired and it is now expired and it's sayin I still need to pay for what I bought with the old card and I don't want to pay twice for the same things that's just stupid I'm goin to get a gift card for the lowest amount so I can still get the free stuff but I don't think I should be responsible to pay for something thy I bought with a card that had the money on it for them to charge bc they debt send out the bill to them when I got the stuff bc there is stuff on it for like Monday saying I need to pay for it when the card didn't even expire till Thursday night

  • What's wrong with the activation server? i just bought my ipad wifi celllular... and have a 3g cellular network connection... when i press the bottom to activate my ipad it says the activation server cannot be reached. what to do then?

    what's wrong with the activation server? i just bought my ipad wifi celllular... and have a 3g cellular network connection... when i press the bottom to activate my ipad it says the activation server cannot be reached. what to do then?

    Hey aries35,
    I found the following that goes over troubleshooting the same issue for the iPhone. I know you have an iPad, but the steps should still apply:
    Perform the following steps:
    Restart the iPhone.
    Try another means of reaching the activation server and attempt to activate.
    Try connecting to a known-good Wi-Fi network if you're unable to activate using a cellular data connection.
    Try connecting to iTunes if you're unable to activate using Wi-Fi.
    Restore the iPhone.
    If you receive an alert message when you attempt to activate your iPhone, try to place the iPhone in recovery mode and perform a restore. If you're still unable to complete the setup assistant due to an activation error, contact Apple for assistance.
    via: iPhone: Troubleshooting activation issues
    http://support.apple.com/kb/TS3424
    Cheers,
    Delgadoh

  • What's wrong with the itunes store UAE? i couldnt buy my favorite songs and movies because there's no "music" and "movies" category. please do something... thanks!

    what's wrong with the itunes store UAE? i couldnt buy my favorite songs and movies because there's no "music" and "movies" category. please do something... thanks!

    You are not addressing Apple here...
    This is a User to User forum...
    iTunes Store: Which types of items can I buy in my country?

  • What's wrong with the fan of my 15 inch retina mbp?

    what's wrong with the fan of my 15 inch retina mbp,when i play a big game like Batman ,the fans are so quiet and keep around 2000rpm,but the temperature of  cpu is up to 80 degrees.(by the way, i have reseted the SMC for many times,but it doesn't work)

    80 degrees F or 80 degrees C?

  • What's wrong with the code?

    public void run()
    try
    {     for(;;)
         mgr = (RTPManager)RTPManager.newInstance();
         mgr.addSessionListener(this);
         mgr.addReceiveStreamListener(this);
         try{  /*****port1 = port2 = 29261, which port is only used in here
         localAddr = new SessionAddress(InetAddress.getLocalHost(), port1);
         destAddr = new SessionAddress(ipAddr, port2);
         }catch(Exception e)
              System.out.println(e + " 4");
         try{
         mgr.initialize(localAddr);
         }catch(Exception e)
         System.out.println(e + " 5");
         //set buffer
         bc = (BufferControl)mgr.getControl("javax.media.control.BufferControl");
         if (bc != null)
         bc.setBufferLength(20);
         try{
              mgr.addTarget(destAddr);
         }catch(Exception e)
         System.out.println(e + " 2");
    catch(Exception e)
         System.out.println(e+ " 3");
    the error when i run the code is like that:
    javax.media.rtp.InvalidSessionAddressException: Can't open local data port: 29261
    5
    java.io.IOException: Address already in use: Cannot bind 2
    which means there is error in :
    mgr.initialize(localAddr);
    mgr.addTarget(destAddr);
    But i don't know what's wrong with the code,
    can any one help me?

    I do not find any problem using the same ports for local and destination address with several unicasts. My problems are others.
    But note that the error is even at constructing the localAddress, I mean before trying the destinationAddress. Thus the reason cannot be the former is already in use. In fact I think the later belongs to a remote hosts. Likely, it is trying to access the destinationAddress through the localAddress, but this has not been constructed properly.

  • What's wrong with the wsdl

    We are trying to create a proxy from the following wsdl file and getting an error message: illegal syntax: API:Parameter BINDING has initial value
    The webservice that we are trying to consume is from TIBCO .
    Can someone please help me to find out what's wrong with the wsdl.
    <?xml version = "1.0" encoding = "UTF-8"?>
    <!--Created by TIBCO WSDL-->
    <wsdl:definitions name = "Untitled" targetNamespace = "http://xmlns.example.com/1268018884234/OperationImpl" xmlns:soap = "http://schemas.xmlsoap.org/wsdl/soap/" xmlns:tns = "http://xmlns.example.com/1268018884234/OperationImpl" xmlns:wsdl = "http://schemas.xmlsoap.org/wsdl/" xmlns:xs = "http://www.w3.org/2001/XMLSchema">
         <wsdl:types/>
         <wsdl:service name = "TIBCO__ABAP">
              <wsdl:port binding = "tns:SOAPEventSourceBinding" name = "SOAPEventSource">
                   <soap:address location = "http://192.168.9.58:10001/TIBCO_ABAP"/>
              </wsdl:port>
         </wsdl:service>
         <wsdl:portType name = "PortType">
              <wsdl:operation name = "Operation">
                   <wsdl:input message = "tns:Input"/>
                   <wsdl:output message = "tns:Output"/>
              </wsdl:operation>
         </wsdl:portType>
         <wsdl:binding name = "SOAPEventSourceBinding" type = "tns:PortType">
              <soap:binding style = "document" transport = "http://schemas.xmlsoap.org/soap/http"/>
              <wsdl:operation name = "Operation">
                   <soap:operation soapAction = "http://192.168.9.58:10001/TIBCO_ABAP" style = "document"/>
                   <wsdl:input>
            <soap:body use="literal" />
          </wsdl:input>
                   <wsdl:output>
            <soap:body use="literal" />
                   </wsdl:output>
              </wsdl:operation>
         </wsdl:binding>
         <wsdl:message name = "Input">
              <wsdl:part name = "Param1" type = "xs:int"/>
              <wsdl:part name = "Param2" type = "xs:int"/>
         </wsdl:message>
         <wsdl:message name = "Output">
              <wsdl:part name = "Result" type = "xs:int"/>
         </wsdl:message>
    </wsdl:definitions>

    Léon Hoeneveld's response works for me.  You will need to download a tool that allows you to edit the WSDL and reorder the values. 
    I've used a freeware tool like notepad++  collapsed all the levels and opened up the <wsdl:definitions xmlns:wsdl... segment and reordered the subgroups beneath it accordingly.
    1. types
    2. message
    3. portType
    4. binding
    5. service
    Thanks again Léon!

  • What's wrong with the following code?

    What's wrong with the following code?
    Circle cir1;
    double rad = cir1.radius

    The circle Object was never instantiated.
    In other words, you have set a declaring of a Circle, but it has not been created in memory yet.
    You will create it using the " = new Circle( PARAMETERS_HERE ); "
    Or some other method that returns a circle.

  • What's wrong with the IOS5 download, it downloads and then after its finished it says server timed out, how do i sort this out

    What's wrong with the IOS5 download, it downloads and then after its finished it says server timed out, how do i sort this out?

    The Firefox versions which come with many Linux distros have the default Mozilla Firefox updater disabled and use the distros built-in updater.
    See this - http://linuxforums.org.uk/netbooks/install-firefox-6-on-an-acer-aspire-one-running-linpus-lite-linux/

  • All of my apple sets (iphone, ipad and computer) cannot connect the app store since yesterday, what's wrong with the app store?

    All of my apple sets (iphone, ipad and computer) cannot connect the app store since yesterday, what's wrong with the app store? do you know? or do you have have the same experience?

    I still have access.  Must be your phone or your internet connection.

  • I can't print using airprint from my iPhone 4.  Everything with the phone and the printer and router are up to date.  I can print from my iPad 2 with no problems.  What's wrong with the iPhone 4?

    I can't print using airprint from my iPhone 4.  Everything with the phone and the printer and router are up to date.  I can print from my iPad 2 with no problems.  What's wrong with the iPhone 4?

    I just wanted to leave a note that it's working now. I'm not sure if it was the latest iTunes update that got it working or that i decided to start a new library instead of using the one i had backed up on Windows 8 (it didn't occur to me to check using the old library when i re-installed iTunes). But if anyone is having this problem, it might be worth trying again with a new installation of iTunes to see if the latest update works for you, and if not, try using a fresh library instead of a backup (by fresh library i mean discard your old library completely and start a new library, not just restore as new iPhone, a whole new library).

  • Is there a problem w/itunes store site? after input my cr.card info, i was told that it cannot verify my address, which is correct, what's wrong with the edit the billing info screen?

    What is wrong with the edit biling info screen. it cannot verify my address. i triple check my address info
    and it is correct.

    Use the email form >  Apple - Support - iTunes Store - Contact Us

Maybe you are looking for

  • HT201250 How do I find out what portable drive was the drive I used for Time Machine Backup?

    Hi, I have 10.7.4 and need to figure out what drive I was using for Time Machine Backup.  I have three drives and I have connected each of them to my macbook pro, but I get an error, "Time Machine Error, The backup disk is not available" when I hit t

  • NEW IPOD NANO NOT WORKING, PLEASE HELP

    Hi Guys, I have the large IPOD (4 YEARS OLD) and bought a 2nd Ipod Nano that's smaller for the gym. I plugged it into my MAC BOOK PRO and it keeps saying it needs to be updated which I press "OK" and then it asks for my password and when I type it in

  • How to disable the Search option in UWL header?

    Hello, I am trying to removed the search option in the standard UWL iView by setting the "Allow Search" property of the standard iView to "No". However this doesn't remove the search option in the UWL header. Is this right property to configure? If a

  • What is the significance of MultiLine check box

    Hi Can any one explain me the importance of MultiLine checkbox in Condion Editor at Interface determination. If possible try to explain with example plz... Thanks

  • Pause & Play Animation When i'm using movie clips- filters

    Pause & Play Animation When i am using movie clips- filters Graphic and movieclips are using for my animation When i Press the pause the movieclip animation not stopped. Any way to apply the filters on graphic I want to apply the filters for particul