Please see http://www.cisco.com/warp/customer/707/idsemailcspm_6155.htmlfor setting up email notifications.the "ip log" option is for capturing packet dumps of conversaions between source and destination of an attack and should NOT normally be config...
is there a lot of multicast traffic on your lan that you are sniffing? there is an issue (not resolved yet) where the iprb0 interface cannot correctly identify certain multicast traffic. The workaround is to swap the interfaces which you have already...
basically, understand that you cannot tcp reset all signatures, because not all signatures are tcp based signatures. Also, it typically does not help to tcp reset a tcp port scan because of the nature of port scans. Tcp resets are good for connection...
there are 2 things you can do:1.remove the 2 registry keysHKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\pendingfilerenameoperation(actually 2 keys sessionmanager & session manager)delete pendingfilerenameoperation and/or rename ...