Re: [Snort-devel] RE : [Snort-sigs] i have only 600 rules in my snort3
Noah Dietrich <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <CA+N0JEw4og_Vr+uQ4BQH47DO+NaG9_STqz6B7EjVXnThN9EnqQ@mail.gmail.com> |
Removing snort-sigs and snort-devel since those distros are not correct for this discussion. Please review my previous email about your pulledpork.conf and the ips_policy setting, this may explain why you don't have as many rules enabled as you would like. your snort.lua and your pulledpork.conf files are located in the default location, you've edited them before and have not moved location. Please see the guide as to their location, If this does not help, please explain clearly why you believe that the talos ruleset has more rules than are being enabled, and why the ips_policy setting does not fix this issue. noah On Thu, Mar 3, 2022 at 8:12 PM Dorian ROSSE via Snort-devel < [email protected]> wrote: > Dear Noah, > > > This weekend I read the snort3 manual, > > Where is the pulledpork.lua ? > > Where is the snort.lua ? > > The week I have no computer, no server, > > Thanks you in advance for your answer, > > Regards. > > > Dorian Rosse. > _______________________________________________ > Snort-devel mailing list > [email protected] > https://lists.snort.org/mailman/listinfo/snort-devel > > Please visit http://blog.snort.org for the latest news about Snort! > _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette