Suricata Alerts
-
Question – Are the Suricata alerts such as:
SURICATA STREAM ESTABLISHED retransmission packet before last ack
real alerts or false positives? This alert repeats itself? Additionally, from time to time I receive other Suricata Streaming alterts. Are these real? Should these alerts and the rules they refer to be disabled? I am using Emerging Threats ETPro rules and receive their alert messages with no problem? Any help in clarifying these alert messages will be appreciated.
-
These are typically noisy rules that can be disabled.