|
Hi Pete,
I'll send the logs for the past two days separately
to support (at). We do run snf2check on every downloaded rulebase, so that
shouldn't be an issue.
The one thing I didn't think to do was to revert to
an old rulebase, but we only keep the previous, so it would have already been
too late when we saw the problem this morning.
Thanks,
Darin. ----- Original Message -----
From: Pete
McNeil
To: Darin Cox
Sent: Tuesday, November 08, 2005 4:03 PM
Subject: Re[4]: [sniffer] Rash of false positives On Tuesday, November 8, 2005, 3:25:20 PM, Darin wrote:
This is highly unusual -- I didn't remove many rules, and normally only one or two would be responsible. If you found that a large number of rules were responsible then something else happend and we need to look at that... I'd need to see your SNF logs from that period since the changes (removals anyway) in the rulebase were very small and unrelated - that just doesn't line up with your description. One thing does-- in the past if snf2check was not used to check a new download then a corrupted rulebase could cause SNF to produce erratic results... since snf2check has been in place we have not seen this. Is it possible that a bad rulebase file got pressed into service on your system? -- probably a look at the logs would help there too since this kind of failure is accompanied by very specific oddities in the logs. Hope this helps, _M |
- Re: [sniffer] Rash of fals... Scott Fisher
- Re: [sniffer] Rash of ... Darrell ([email protected])
- Re: [sniffer] Rash... Darin Cox
- Re[2]: [sniffer] R... Pete McNeil
- Re: [sniffer] Rash of false positiv... Paul Lushinsky
- Re: [sniffer] Rash of false po... Darin Cox
- Re: [sniffer] Rash of false positiv... Darin Cox
- Re[2]: [sniffer] Rash of false... Pete McNeil
- Re: Re[2]: [sniffer] Rash ... Darin Cox
- Re[4]: [sniffer] Rash ... Pete McNeil
- Re: Re[4]: [sniffe... Darin Cox
- Re: Re[4]: [sniffe... Richard Farris
- RE: Re[4]: [s... John Moore
- Re[6]: [s... Pete McNeil
- Re: Re[6]... Richard Farris
- Re: Re[4]... Darin Cox
- RE: Re[4]... John Moore
- Re[6]: [s... Pete McNeil
- Re: [snif... Matt
- RE: [snif... John Moore
- Re: [snif... Serge
