Snort mailing list archives

Re: Customization of rules


From: Erek Adams <erek () theadamsfamily net>
Date: Fri, 1 Feb 2002 10:48:22 -0800 (PST)

On Fri, 1 Feb 2002, Chip Kelly wrote:

I'm just getting comfortable with the changes that I've made to the rules
that are supplied with 1.8.3. Most of the changes are localized in
local.rules, but I have also made changes to the way some of the other rules
work in order to reduce false positives in my environment. My question - how
do I preserve the customized rules in files other than local.rules when I
update my rule sets either from an update to snort or simply an update to my
rules files? I'm not looking forward to handling each customization
individually. -chip

Suggestion:  Build a custom.rules file.  Any rule that gets changed, gets
copied to custom.rules with comments on how/why it was changed.  Then in the
original .rules file that the rule came from, you just comment it out.  That
allows you to run a diff against the current rules and the updated rules.  The
rules that you've customized will show up as different, since they are
commented out.  That lets you have one place to modify rules and one place to
keep up with them.

YMMV, but that works for some....  Good luck!

-----
Erek Adams
Nifty-Type-Guy
TheAdamsFamily.Net


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: