Snort mailing list archives
snort snort don't recognize plugin sid set by me
From: Daniel Lopez <danilogo1991 () gmail com>
Date: Fri, 15 May 2015 00:26:34 +0200
Hi I created a new rule for snort with the following sid:10001 i recieve alerts trigered by this rule in OSSIM web interface but it appears as Generic event. When i open the event detail window i find the event type id is changed to 2000000000 and payload contains [Unknown plugin sid: 10001]..... Problem is that i can't differentiate between alerts triggered by rules created by me in a correlation directive. How can i set a proper name for the rule rather than Generic Event? How can i make the system to reconize event type set by me? Thanks
------------------------------------------------------------------------------ One dashboard for servers and applications across Physical-Virtual-Cloud Widest out-of-the-box monitoring support with 50+ applications Performance metrics, stats and reports that give you Actionable Insights Deep dive visibility with transaction tracing using APM Insight. http://ad.doubleclick.net/ddm/clk/290420510;117567292;y
_______________________________________________ Snort-sigs mailing list Snort-sigs () lists sourceforge net https://lists.sourceforge.net/lists/listinfo/snort-sigs http://www.snort.org Please visit http://blog.snort.org for the latest news about Snort!
Current thread:
- snort snort don't recognize plugin sid set by me Daniel Lopez (May 14)
- Re: snort snort don't recognize plugin sid set by me Y M (May 15)