Snort mailing list archives
Re: metadata questions
From: Joel Esler <jesler () sourcefire com>
Date: Fri, 31 May 2013 14:28:14 -0400
On May 31, 2013, at 1:31 PM, "Morris, Shane (US SSA)" <shane.morris () baesystems com> wrote:
I think your right if I use a metadata with some informational key like “metadata:author me” it should because like you said Snort doesn’t require you to specify a service. I know this is a bit out of scope for this forum but could you tell me how I could do this in SF 5.x because you have to specify a service?
Okay, so some clarification, if the rule specifies a service in 5.x, it will only be evaluated if the service matches. -- Joel Esler Senior Research Engineer, VRT OpenSource Community Manager Sourcefire
------------------------------------------------------------------------------ Get 100% visibility into Java/.NET code with AppDynamics Lite It's a free troubleshooting tool designed for production Get down to code-level detail for bottlenecks, with <2% overhead. Download for free and get started troubleshooting in minutes. http://p.sf.net/sfu/appdyn_d2d_ap2
_______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- metadata questions Morris, Shane (US SSA) (May 30)
- <Possible follow-ups>
- Re: metadata questions Joel Esler (May 30)
- Re: metadata questions Morris, Shane (US SSA) (May 30)
- Re: metadata questions Joel Esler (May 31)
- Re: metadata questions Morris, Shane (US SSA) (May 31)
- Re: metadata questions Joel Esler (May 31)