Lists the configuration options for intrusion performance statistic logging settings and troubleshooting options.
This reference provides information about intrusion performance statistic logging configuration options, including sample time settings, minimum packet requirements, and troubleshooting options for logging session and protocol distribution data.
Sample time (seconds) and minimum number of packets
When the number of seconds specified elapses between performance statistics updates, the system verifies it has analyzed the specified number of packets. If it has, the system updates performance statistics. Otherwise, the system waits until it analyzes the specified number of packets.
Configuring a very low value, such as one second, for the sample time can greatly impact the device. The device may experience disk space issues, and its operation may be affected by the volume of performance statistics logged. To avoid these issues, do not set a very low value.
Troubleshooting options: log session/protocol distribution
Support might ask you during a troubleshooting call to log protocol distribution, packet length, and port statistics.
Do not enable Log Session/Protocol Distribution unless instructed to by Support. Note that for Classic devices only, enabling or disabling Log Session/Protocol Distribution restarts the Snort process when you deploy configuration changes, temporarily interrupting traffic inspection. Whether traffic drops during this interruption or passes without further inspection depends on how the assigned device handles traffic.
Troubleshooting options: summary
Support might ask you during a troubleshooting call to configure the system to calculate the performance statistics only when the Snort process is shut down or restarted. To enable this option, you must also enable the Log Session/Protocol Distribution troubleshooting option.
Do not enable Summary unless instructed to do so by Support.