Re: Progress

Noah Dietrich <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <CA+N0JExzpsm0d0Xrqu2zj6hXcJxPcsKv_TNguzG-KxfjWi6RHg@mail.gmail.com>
Hello:

As Joel noted: the ET (Emerging Threats) ruleset doesn't have a version
that's compatible with snort 3 (snort 2 and snort 3 rules are not
compatible).  If you really want ET rules in Snort3: you'd need to use
*snort2lua *to convert them to snort3 format and then add that modified
file as your local.rules file for PP3 to add to your pulledpork.rules
(example conversion:
https://blog.snort.org/2020/10/how-to-use-snort2lua.html)

The LightSPD package is what you should be using in your pulledpork.conf
over the registered ruleset, it's working correctly.

The only feature we still need to add to PP3 is the modifysid file
functionality, everything else should be working correctly.  We still have
some bits to clean up and more error checking to add, but the base
functionality is there and stable.  Once ET releases a snort3
compatible ruleset, we'll add it into PP3.

NOTE: if anyone has issues with PP3, please submit a bug report on github:
https://github.com/shirkdog/pulledpork3/issues

Noah



On Wed, Mar 2, 2022 at 11:43 AM James Lay <[email protected]> wrote:

> On 2022-03-02 14:36, Joel Esler wrote:
>
> Inline:
>
> On Mar 2, 2022, at 3:04 PM, James Lay <[email protected]>
> wrote:
>
> Team,
>
> As I'm sure the snort 2 EOL is coming this year, I'm asking for
> status for a few things:
>
>
> Snort 2 EOL is not on the horizon, like, ever, afaik.
>
> ET rules integration?
>
>
> ET rules do not have a Snort 3 version, but there is a tool that can
> convert rules to snort 3 format.
>
> Actual examples of directives in the documentation?
>
> Pullpork is now stable and working with the lightspeed packages, for
> me at least, so the above are my only outstanding items.  Thank you.
>
>
> James _______________________________________________
> Snort-users mailing list
> [email protected]
> Go to this URL to change user options or unsubscribe:
> https://lists.snort.org/mailman/listinfo/snort-users
>
> To unsubscribe, send an email to:
> [email protected]
>
> Please visit http://blog.snort.org to stay current on all the latest
> Snort news!
>
> Please follow these rules:
> https://snort.org/faq/what-is-the-mailing-list-etiquette
>
> Thanks Joel!  I'll take a look at the tool again...last time I used it the
> output was not very usable/readable.  Sounds like good news on the EOL
> front as well :)
>
> James
> _______________________________________________
> Snort-users mailing list
> [email protected]
> Go to this URL to change user options or unsubscribe:
> https://lists.snort.org/mailman/listinfo/snort-users
>
>         To unsubscribe, send an email to:
>         [email protected]
>
> Please visit http://blog.snort.org to stay current on all the latest
> Snort news!
>
> Please follow these rules:
> https://snort.org/faq/what-is-the-mailing-list-etiquette
>

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.