Snort mailing list archives
Enabling Only Applicable Rules
From: bobby <architectofthefuture () gmail com>
Date: Fri, 12 May 2017 20:32:26 -0400
I am running snort, and have the community rules. If I am running the HTTP service, how do I locate the rules that I need to activate/that apply to me? Do I just do a ls | grep ' HTTP ' on the rules? What is the best way to do this since there are thousands and thousands of rule sets? How does one go about customizing the rules to ones' network? ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- Enabling Only Applicable Rules bobby (May 12)
- Re: Enabling Only Applicable Rules Marcin Dulak (May 14)
- Message not available
- Re: Enabling Only Applicable Rules Marcin Dulak (Jun 06)
- Re: Enabling Only Applicable Rules bobby (Jun 06)
- Re: Enabling Only Applicable Rules Marcin Dulak (Jun 06)
- Message not available
- Re: Enabling Only Applicable Rules Marcin Dulak (May 14)