Refer to the exhibit. What logical source device generated these events?
Snort intrusion events include signature messages with Generator ID, Snort ID, and revision in the (GID:SID:revision) format. Shellcode and policy signatures are produced by an intrusion detection or prevention engine that inspects network traffic, so the logical device is an IDS/IPS.
(GID:SID:revision)
Community Discussion