Hi
3 things...
Are you sure you are not seeing a backlog from the previous hits?
In your post you had a # in front of the rule. Make sure that's not the case in the threshold.conf file.
And afterwards remember to sudo rule-update to have the change to take effect.
Regards,
Lysemose
--
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at http://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/d/optout.