Thank u.I have to use the port specified by the POP3&IMAP protocol for detection first.
About the first question.
1.when i use the rule
alert smtp any any <> any any (msg:"smtp event"; sid:1000015; rev:10;)
.smtp event more than wireshark displayed.
I found the reason.The rule has led to an increase for events.
I delete the rules and solve the problem.
And i found a new problem.Some ftp event appeared when i detect POP3