With the new snort being downloaded in full for every IPS update, will we receive a mail notification about snort restarting, so far today I have received 2 notifications?
To my knowledge snort can operate as IPS or IDS. As per the error message you've provided , it seems that it's now operating in IDS mode which means that it cannot stop malicious traffic from single-packet attacks )