Hi Pete/community, If I understand things correctly then the detection of a panick rule is local to the system. So a few systems may have enough traffic to see that a rule is acting wrong and assume a panick for that rule. According to the WiKi that information is sent automatically to the folks at armresearch, but... As far as I know there is yet no mechanism to get that information automatically to the Sniffer comunity.
Might it be a good idea to propagate rule panic info via tha GRUdb mechanism? As far as I understand information gets updated and transmitted a lot faster then rulebase updates. Met vriendelijke groet, Bonno Bloksma senior systeembeheerder tio hogeschool hospitality en toerisme begijnenhof 8-12 / 5611 el eindhoven t 040 296 28 28 / f 040 237 35 20 b.blok...@tio.nl / www.tio.nl