Snort mailing list archives

Re: BASE rule display


From: firewalZ <firewalz () gmail com>
Date: Tue, 17 Nov 2009 08:45:33 -0500

Thanks for your response, I went to the link as suggested and added
2899096 as a feature request for the next release.

"Details:
The ability to view a rule, in its entirety, which triggers an event. This
would aid in the learning process, increase a users ability to tune rules
and understand why specific traffic is matching a particular rule."



On Tue, Nov 17, 2009 at 7:42 AM, Randal T. Rioux <randy () procyonlabs com> wrote:
This is a pretty good idea. If you could, please go to the feature
request page at SourceForge and add this. I'll take a look at it and see
what I can do to implement this into the next release:

http://sourceforge.net/tracker/?group_id=103348&atid=635585

While you're at it, if you're a regular user you might want to join
BASE's own mailing list, as this one is Snort-specific:

https://lists.sourceforge.net/lists/listinfo/secureideas-base-user

Thanks!
Randy


Joel Esler wrote:
Base does not have that present functionality. They provide the
ability to link to a rule.

J

On Monday, November 16, 2009, firewalZ <firewalz () gmail com> wrote:
Im a bit new to Snort/Base and Im wondering if there a way to get BASE
to display the full text of a rule that fires an alert, this would
really help the learning process.


------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
trial. Simplify your report design, integration and deployment - and focus on 
what you do best, core application coding. Discover what's new with
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: