Suricata Alerts
Question – Are the Suricata alerts such as:
SURICATA STREAM ESTABLISHED retransmission packet before last ack
real alerts or false positives? This alert repeats itself? Additionally, from time to time I receive other Suricata Streaming alterts. Are these real? Should these alerts and the rules they refer to be disabled? I am using Emerging Threats ETPro rules and receive their alert messages with no problem? Any help in clarifying these alert messages will be appreciated.
These are typically noisy rules that can be disabled.