i can´t reproduce it. Are you sure that your attacks were not fetched by the packetfilter?
If you are unsure attack your victim again and look in the ips.log whether the asg will log something or not.
i can´t reproduce it. Are you sure that your attacks were not fetched by the packetfilter?
If you are unsure attack your victim again and look in the ips.log whether the asg will log something or not.
I have logged a similar complaint in another thread. Under I think the last 3 betas there hasn't anything reported in the graphs for attacks or attempted attacks.
Hi,
good you added some log lines, this makes debugging a lot easier. Snort ID (sid) == 0 and group == 0 indicate a preprocessor alert. Since pre-V7, preprocessor alerts are ignored by the reporting because preprocessors are very noisy and seldom contain useful information.
I can't actually prove that these relate to the entries in the daily report because none of these have the IP address shown in the daily report. There are 2 entires earlier in the log that might be of interest as well, but they also don't have the IP address shown in the report.
the Log you parsed contain just warning messages from Http Inspect preprocessor.
E.g. OVERSIZE REQUEST-URI DIRECTORY just warn you because the size of URL + params are greater then the value in the config from http inspect preprocessor.
Like Andreas said its a general warn message mostly w/o any important background.
And for that reason this warn messages will not displayed in " Top blocked attacks "