Snort mailing list archives

sid-msg.map question


From: Rich Adamson <radamson () routers com>
Date: Thu, 26 May 2005 11:09:25 -0600


snort v2.3 with oinkmaster v1.2 on win32 box with dual sensor nic's

Is the sid-msg.map file actually used by snort?  If so, is there
a way to specify the exact location of the file?

Background: running snort with two sensor nics. The rules for one
interface are in \rules directory while the rules for the second
interface are in \rules2 (and both are tailored to there respective
functions). When using oinkmaster, I download both snort and bleeding-
snort rules, then generate the sid-msg.map using the create-sidmap.pl
script with oinkmaster. Should these maps be in the respective "rules"
directory or moved to snort\etc directory? I've been moving them, but
that now creates an issue if the \rules and \rules2 directories
contain different tailored rule sets.

Thoughts anyone?




-------------------------------------------------------
This SF.Net email is sponsored by Yahoo.
Introducing Yahoo! Search Developer Network - Create apps using Yahoo!
Search APIs Find out how you can build Yahoo! directly into your own
Applications - visit http://developer.yahoo.net/?fr=offad-ysdn-ostg-q22005
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: