Snort mailing list archives

Re: I cannot extract rules in /etc/snort/rules


From: "Joel Esler \(jesler\) via Snort-users" <snort-users () lists snort org>
Date: Sat, 13 Oct 2018 17:44:44 +0000

It is well documented in the .conf file and readmes.

Sent from my iPhone

On Oct 13, 2018, at 13:41, Dorian ROSSE <dorianbrice () hotmail fr<mailto:dorianbrice () hotmail fr>> wrote:

How to use pulledpork ?

Dorian Rosse.

________________________________
De : Joel Esler (jesler) <jesler () cisco com<mailto:jesler () cisco com>>
Envoyé : samedi, octobre 13, 2018 19:39
À : daytonpa
Cc : Dorian ROSSE; snort-users-owner () lists snort org<mailto:snort-users-owner () lists snort org>; snort-users () 
lists snort org<mailto:snort-users () lists snort org>
Objet : Re: [Snort-users] I cannot extract rules in /etc/snort/rules

Let me ask this... why are you not using pulledpork?   That’s what we design the ruleset to work with.

Sent from my iPhone

On Oct 13, 2018, at 13:22, daytonpa <daytonpa () gmail com<mailto:daytonpa () gmail com>> wrote:

Which rule files are you extracting?  Depending on the rules, you will need an "oinkcode" to properly use them.

On Sat, Oct 13, 2018, 1:10 PM Dorian ROSSE <dorianbrice () hotmail fr<mailto:dorianbrice () hotmail fr>> wrote:
Hello IT workers,


As the title :

I cannot extract rules in /etc/snort/rules which the command line :
tar -xvzf snortrules-snapshot-<version>.tar.gz -C /etc/snort/rules

I edited the version string 😉

But I cannot extract the rules as after create the snort and the rules folder in etc

(because snort and rules cannot be in etc…)

Thank you in advance to repair the problem,

Regards.


Dorian ROSSE.
_______________________________________________
Snort-users mailing list
Snort-users () lists snort org<mailto:Snort-users () lists snort org>
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

        To unsubscribe, send an email to:
        snort-users-leave () lists snort org<mailto:snort-users-leave () lists snort org>

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
_______________________________________________
Snort-users mailing list
Snort-users () lists snort org
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

        To unsubscribe, send an email to:
        snort-users-leave () lists snort org

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Current thread: