Snort mailing list archives

Problems disabling rule categories with PulledPork


From: Mike Kun <mkun () akamai com>
Date: Tue, 08 Mar 2011 15:20:50 -0500

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

We're running pulledpork for rulemanagemnts and use it to pull down VRT
and ETPro rulesets.
We'd like to be able to disable All the ETPro rules and enable them
slowly for tuning purposes.
Is there any way to do this without disabling the VRT rules as well.
For example, if I add "ftp" to the disablesid file, that should disable
all FTP rules for both VRT and ETPro.
Suppose I only wanted to disable the ETPro Ftp rules, how could that be
handled?

- -Mike
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQEcBAEBAgAGBQJNdo+iAAoJEMhWEt1OJPG/gKQH/02dS+GBch9D0BKLo3PWkQ2b
2gLiOqQ9+aHR5KCJPI5ggOWvLJOExS8OVIO/biQw8b/88dAVcwWAKTkK9otxBT9i
qly6uH2WBfYHEyKTu65Ur3R1SJSN6a4Ol54N1BINZTAph9rRsGEchNcHVYngbwXB
9AKx3FxRAHtHo0g5PawER9A/EZGH6czXxKr4Ai13D4RaZ6/YbwrQJTMB9qN4bKpR
4AT0RJ6y/LlapMbgJkrCC2iG7PPa1CP7vP7fg62ZqfqaABDktqCM+oS8lGVlTK3p
Nie1GRTQgJxd+W0VZ/WfFhDyElHV7RO4P1VfGugIWrTk319k0GiEZSXi1Fxw634=
=UrLk
-----END PGP SIGNATURE-----

------------------------------------------------------------------------------
What You Don't Know About Data Connectivity CAN Hurt You
This paper provides an overview of data connectivity, details
its effect on application quality, and explores various alternative
solutions. http://p.sf.net/sfu/progress-d2d
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: