# Understanding Stats.log against Syn Flood Attacks

**URL:** <https://forum.suricata.io/t/understanding-stats-log-against-syn-flood-attacks/1012>\
**Category:** Help\
**Created:** [January 25, 2021, 12:18pm UTC](https://forum.suricata.io/t/understanding-stats-log-against-syn-flood-attacks/1012 "2021-01-25T12:18:34Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cagri](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/cagri/32/574_2.png) [@Cagri](https://forum.suricata.io/u/Cagri)\
**Post date:** [January 25, 2021, 12:18pm UTC](https://forum.suricata.io/t/understanding-stats-log-against-syn-flood-attacks/1012/1 "2021-01-25T12:18:34Z")

</div>

Hi All,

I am new to Suricata. I am testing Suricata 6.0.1 on Windows 10 with Snort community signatures for the comparison. I attack with Hping3 to Snort and Suricata in detect mode on similar PCs.  
ie. I send 1000 Syn Packets to both hence Snort capture 1000 Syn packets and alerts 1000 and Suricata captures 1000 Syn packets but alerts 6 as seen below. Could you please help to understand the logs properly and if needs any improvement for the configuration.

Thanks.

## Counter | TM Name | Value

capture.kernel\_packets | Total | 1004  
decoder.pkts | Total | 1005  
decoder.bytes | Total | 174378  
decoder.ipv4 | Total | 1003  
decoder.ethernet | Total | 1005  
decoder.tcp | Total | 1000  
decoder.udp | Total | 3  
decoder.avg\_pkt\_size | Total | 173  
decoder.max\_pkt\_size | Total | 174  
flow.tcp | Total | 1000  
flow.udp | Total | 1  
flow.wrk.spare\_sync\_avg | Total | 100  
flow.wrk.spare\_sync | Total | 12  
tcp.syn | Total | 1000  
detect.alert | Total | 6  
app\_layer.flow.failed\_udp | Total | 1  
flow.mgr.full\_hash\_pass | Total | 1  
flow.spare | Total | 10100  
flow.mgr.rows\_maxlen | Total | 1  
flow.mgr.flows\_checked | Total | 119  
flow.mgr.flows\_notimeout | Total | 119  
tcp.memuse | Total | 2293760  
tcp.reassembly\_memuse | Total | 393216  
flow.memuse | Total | 7177504

---

<div class="post-metadata">

**Author:** ![vjulien](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/vjulien/32/4_2.png) [@vjulien](https://forum.suricata.io/u/vjulien)\
**Post date:** [January 25, 2021, 7:13pm UTC](https://forum.suricata.io/t/understanding-stats-log-against-syn-flood-attacks/1012/2 "2021-01-25T19:13:21Z")

</div>

Can you post the rule that you’re expecting to match?

---

<div class="post-metadata">

**Author:** ![Cagri](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/cagri/32/574_2.png) [@Cagri](https://forum.suricata.io/u/Cagri)\
**Post date:** [January 25, 2021, 9:26pm UTC](https://forum.suricata.io/t/understanding-stats-log-against-syn-flood-attacks/1012/3 "2021-01-25T21:26:39Z")

</div>

Actually I am not pretty sure which rule but snort can identify it.  
maybe these two;  
alert ( msg: “STREAM5\_SYN\_ON\_EST”; sid: 1; gid: 129; rev: 1; metadata: rule-type preproc ; classtype:bad-unknown; )  
alert ( msg: “STREAM5\_DATA\_ON\_SYN”; sid: 2; gid: 129; rev: 1; metadata: rule-type preproc ; reference: cve,2009-1157; reference: bugtraq, 34429; classtype:protocol-command-decode; )

my snort logs and attack command;

sudo hping3 192.168.x.x -q -n -d 120 -S --faster --rand-source -w 64 -p xxx -c 100

# Snort ran for 0 days 0 hours 0 minutes 17 seconds Pkts/sec: 6

# Packet I/O Totals: Received: 109 Analyzed: 109 (100.000%) Dropped: 0 ( 0.000%) Filtered: 0 ( 0.000%) Outstanding: 0 ( 0.000%) Injected: 0

# Breakdown by protocol (includes rebuilt packets): Eth: 109 (100.000%) VLAN: 0 ( 0.000%) IP4: 100 ( 91.743%) Frag: 0 ( 0.000%) ICMP: 0 ( 0.000%) UDP: 0 ( 0.000%) TCP: 100 ( 91.743%) IP6: 0 ( 0.000%) IP6 Ext: 0 ( 0.000%) IP6 Opts: 0 ( 0.000%) Frag6: 0 ( 0.000%) ICMP6: 0 ( 0.000%) UDP6: 0 ( 0.000%) TCP6: 0 ( 0.000%) Teredo: 0 ( 0.000%) ICMP-IP: 0 ( 0.000%) EAPOL: 0 ( 0.000%) IP4/IP4: 0 ( 0.000%) IP4/IP6: 0 ( 0.000%) IP6/IP4: 0 ( 0.000%) IP6/IP6: 0 ( 0.000%) GRE: 0 ( 0.000%) GRE Eth: 0 ( 0.000%) GRE VLAN: 0 ( 0.000%) GRE IP4: 0 ( 0.000%) GRE IP6: 0 ( 0.000%) GRE IP6 Ext: 0 ( 0.000%) GRE PPTP: 0 ( 0.000%) GRE ARP: 0 ( 0.000%) GRE IPX: 0 ( 0.000%) GRE Loop: 0 ( 0.000%) MPLS: 0 ( 0.000%) ARP: 9 ( 8.257%) IPX: 0 ( 0.000%) Eth Loop: 0 ( 0.000%) Eth Disc: 0 ( 0.000%) IP4 Disc: 0 ( 0.000%) IP6 Disc: 0 ( 0.000%) TCP Disc: 0 ( 0.000%) UDP Disc: 0 ( 0.000%) ICMP Disc: 0 ( 0.000%) All Discard: 0 ( 0.000%) Other: 0 ( 0.000%) Bad Chk Sum: 0 ( 0.000%) Bad TTL: 0 ( 0.000%) S5 G 1: 0 ( 0.000%) S5 G 2: 0 ( 0.000%) Total: 109

Action Stats:  
Alerts: 100 ( 91.743%)  
Logged: 100 ( 91.743%)  
Passed: 0 ( 0.000%)  
Limits:  
Match: 0  
Queue: 0  
Log: 0  
Event: 0  
Alert: 0  
Verdicts:  
Allow: 109 (100.000%)

---

<div class="post-metadata">

**Author:** ![Cagri](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/cagri/32/574_2.png) [@Cagri](https://forum.suricata.io/u/Cagri)\
**Post date:** [January 27, 2021, 11:21am UTC](https://forum.suricata.io/t/understanding-stats-log-against-syn-flood-attacks/1012/4 "2021-01-27T11:21:06Z")

</div>

@vjulien or anyone has an idea?

---

<div class="post-metadata">

**Author:** ![Cagri](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/cagri/32/574_2.png) [@Cagri](https://forum.suricata.io/u/Cagri)\
**Post date:** [January 27, 2021, 6:47pm UTC](https://forum.suricata.io/t/understanding-stats-log-against-syn-flood-attacks/1012/5 "2021-01-27T18:47:38Z")

</div>

I write a new rule;  
alert tcp any any → $HOME\_NET any (msg:“SYN Flood”; flags:S; flow: stateless; detection\_filter: track by\_dst, count 1000, seconds 1; GID:1; sid:10000002; rev:001; classtype:attempted-dos;)

But this time detect.alert is disappeared from stats.log.

---

<div class="post-metadata">

**Author:** ![Andreas\_Herz](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/andreas_herz/32/52_2.png) [@Andreas\_Herz](https://forum.suricata.io/u/Andreas_Herz)\
**Post date:** [January 30, 2021, 7:34pm UTC](https://forum.suricata.io/t/understanding-stats-log-against-syn-flood-attacks/1012/6 "2021-01-30T19:34:45Z")

</div>

What do you want to know about the stats.log exactly?  
There are different log files, for example fast.log and eve.json where you would also see the alerts that trigger.

---

<div class="post-metadata">

**Author:** ![Cagri](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/cagri/32/574_2.png) [@Cagri](https://forum.suricata.io/u/Cagri)\
**Post date:** [January 30, 2021, 7:49pm UTC](https://forum.suricata.io/t/understanding-stats-log-against-syn-flood-attacks/1012/7 "2021-01-30T19:49:51Z")

</div>

Stats.log is enough for now but if you suggest any simple use app. much appreciate for the alerts on windows.

I need to understand why the alert is 6.  
What should I do.

---

<div class="post-metadata">

**Author:** ![Andreas\_Herz](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/andreas_herz/32/52_2.png) [@Andreas\_Herz](https://forum.suricata.io/u/Andreas_Herz)\
**Post date:** [January 30, 2021, 7:54pm UTC](https://forum.suricata.io/t/understanding-stats-log-against-syn-flood-attacks/1012/8 "2021-01-30T19:54:59Z")

</div>

I would start with the eve.json alert output and/or fast.log to see what packets have hit which rule. You should have those 6 alerts in there and could use that to find the reason for the 6 hits.
