Intrusion performance statistic logging configuration
This reference provides information about intrusion performance statistic logging configuration options, including sample time settings, minimum packet requirements, and troubleshooting options for logging session and protocol distribution data.
Sample time (seconds) and minimum number of packets
When the number of seconds specified elapses between performance statistics updates, the system verifies it has analyzed the specified number of packets. If it has, the system updates performance statistics. Otherwise, the system waits until it analyzes the specified number of packets.
Caution | Configuring a very low value, such as one second, for the sample time can greatly impact the device. The device may experience disk space issues, and its operation may be affected by the volume of performance statistics logged. To avoid these issues, do not set a very low value. |
Troubleshooting options: log session/protocol distribution
Support might ask you during a troubleshooting call to log protocol distribution, packet length, and port statistics.
Caution | Do not enable Log Session/Protocol Distribution unless instructed to by Support. |
Troubleshooting options: summary
Support might ask you during a troubleshooting call to configure the system to calculate the performance statistics only when the Snort process is shut down or restarted. To enable this option, you must also enable the Log Session/Protocol Distribution troubleshooting option.
Caution | Do not enable Summary unless instructed to do so by Support. |