RFI Honey Net

 



Prob. de query : select count(*) as sig_occurence, signature, sig_sid, brep_event.sig_name, brep_event.sig_priority , count(distinct(ip_src)) as ip_src_occurence from brep_event left join signature on brep_event.signature=signature.sig_id WHERE timestamp between '2012-02-11 18:57:10' AND '2012-02-12 18:57:10' AND brep_event.sig_class_id='2' AND signature.sig_sid!='2002997' AND signature.sig_sid!='2009714' AND signature.sig_sid!='2001087' AND signature.sig_sid!='7070' AND signature.sig_sid!='1738' AND signature.sig_sid!='2009288' AND signature.sig_sid!='1071' group by sig_sid order by sig_occurence desc limit 20
TOP 20 24h signatures occurences vs IP occurences
Occurence(s) Message IP occurence