By the way, how are your alerts doing so far? I have 6 sensors and i get weird alerts with each of them.
Sometimes i get the same alert over and over again. For example host X runs ssh (or whatever) on tcp port X.
Also several of my sensors tell me that a specific MAC adress is associated with different IP addresses that has nothing to do with it. And all of that even on the latest version at the moment (6.6) which resolved other issues for me.
Message was edited by: feblex on 8/26/13 10:16:36 PM CDT