[logs] too many false alarms

Stefano Zanero zanero at elet.polimi.it
Fri Jan 25 11:35:55 PST 2008


Marcus J. Ranum wrote:

> "False alarm" is when the sensor/IDS/monitor raises an alert that is

I would suggest "noncontextual alert", just to get away from the "false"
word.

> technical staff to go "get another opinion from a REAL IDS expert."

Do they know how close to death they were ? :D

Stefano


More information about the LogAnalysis mailing list