Can someone explain how traffic is matched to Snort ID's? i've seen some confiker alerts and by my understanding, they are being alerted based on the SID, but its not clear what exactly in the traffic they are alerting on. As you can see:
Snort :: they have a tendancy for FP. Based on the URLs visited I am leaning that way on my analysis as I dont see anything malicious in the traffic, I want to make sure I am not missing anything.