Re: Progress
Noah Dietrich <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <CA+N0JExzpsm0d0Xrqu2zj6hXcJxPcsKv_TNguzG-KxfjWi6RHg@mail.gmail.com> |
Hello: As Joel noted: the ET (Emerging Threats) ruleset doesn't have a version that's compatible with snort 3 (snort 2 and snort 3 rules are not compatible). If you really want ET rules in Snort3: you'd need to use *snort2lua *to convert them to snort3 format and then add that modified file as your local.rules file for PP3 to add to your pulledpork.rules (example conversion: https://blog.snort.org/2020/10/how-to-use-snort2lua.html) The LightSPD package is what you should be using in your pulledpork.conf over the registered ruleset, it's working correctly. The only feature we still need to add to PP3 is the modifysid file functionality, everything else should be working correctly. We still have some bits to clean up and more error checking to add, but the base functionality is there and stable. Once ET releases a snort3 compatible ruleset, we'll add it into PP3. NOTE: if anyone has issues with PP3, please submit a bug report on github: https://github.com/shirkdog/pulledpork3/issues Noah On Wed, Mar 2, 2022 at 11:43 AM James Lay <[email protected]> wrote: > On 2022-03-02 14:36, Joel Esler wrote: > > Inline: > > On Mar 2, 2022, at 3:04 PM, James Lay <[email protected]> > wrote: > > Team, > > As I'm sure the snort 2 EOL is coming this year, I'm asking for > status for a few things: > > > Snort 2 EOL is not on the horizon, like, ever, afaik. > > ET rules integration? > > > ET rules do not have a Snort 3 version, but there is a tool that can > convert rules to snort 3 format. > > Actual examples of directives in the documentation? > > Pullpork is now stable and working with the lightspeed packages, for > me at least, so the above are my only outstanding items. Thank you. > > > James _______________________________________________ > Snort-users mailing list > [email protected] > Go to this URL to change user options or unsubscribe: > https://lists.snort.org/mailman/listinfo/snort-users > > To unsubscribe, send an email to: > [email protected] > > Please visit http://blog.snort.org to stay current on all the latest > Snort news! > > Please follow these rules: > https://snort.org/faq/what-is-the-mailing-list-etiquette > > Thanks Joel! I'll take a look at the tool again...last time I used it the > output was not very usable/readable. Sounds like good news on the EOL > front as well :) > > James > _______________________________________________ > Snort-users mailing list > [email protected] > Go to this URL to change user options or unsubscribe: > https://lists.snort.org/mailman/listinfo/snort-users > > To unsubscribe, send an email to: > [email protected] > > Please visit http://blog.snort.org to stay current on all the latest > Snort news! > > Please follow these rules: > https://snort.org/faq/what-is-the-mailing-list-etiquette > _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette