Snort mailing list archives
Re: Customization of rules
From: Erek Adams <erek () theadamsfamily net>
Date: Fri, 1 Feb 2002 10:48:22 -0800 (PST)
On Fri, 1 Feb 2002, Chip Kelly wrote:
I'm just getting comfortable with the changes that I've made to the rules that are supplied with 1.8.3. Most of the changes are localized in local.rules, but I have also made changes to the way some of the other rules work in order to reduce false positives in my environment. My question - how do I preserve the customized rules in files other than local.rules when I update my rule sets either from an update to snort or simply an update to my rules files? I'm not looking forward to handling each customization individually. -chip
Suggestion: Build a custom.rules file. Any rule that gets changed, gets copied to custom.rules with comments on how/why it was changed. Then in the original .rules file that the rule came from, you just comment it out. That allows you to run a diff against the current rules and the updated rules. The rules that you've customized will show up as different, since they are commented out. That lets you have one place to modify rules and one place to keep up with them. YMMV, but that works for some.... Good luck! ----- Erek Adams Nifty-Type-Guy TheAdamsFamily.Net _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Customization of rules Chip Kelly (Feb 01)
- Re: Customization of rules Erek Adams (Feb 01)
- <Possible follow-ups>
- RE: Customization of rules Russell Fulton (Feb 02)