Re: snort 3

"Steve Chew \(stechew\) via Snort-users" <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <BL1PR11MB5397AD8BEAC68573488575DBBBF89@BL1PR11MB5397.namprd11.prod.outlook.com>
Albert,
     Could you send a pcap of the traffic that's causing the alerts along with the alert output?

          Steve
________________________________
From: Snort-users <[email protected]> on behalf of Al Lewis (allewi) via Snort-users <[email protected]>
Sent: Monday, April 25, 2022 4:30 PM
To: Albert O'Balsam <[email protected]>; [email protected] <[email protected]>
Subject: Re: [Snort-users] snort 3

Hello,

by_src should be in quotes but either way it looks like a bug.

We will investigate some more and get back to you.

Albert Lewis
ENGINEER.SOFTWARE ENGINEERING
Cisco Systems Inc.
Email: [email protected]



On 4/25/22, 3:15 PM, "Snort-users on behalf of Albert O'Balsam via Snort-users" <[email protected] on behalf of [email protected]> wrote:


    Hi,

    I wonder if anyone can help me.

    I'm experimenting with the suppression functionality of snort 3. I've
    googled, read the documentation multiple times, and have a configuration
    that is accepted by snort, but it doesn't seem to work they way I'd expect
    it to.

    So for example, if I setup the supress section to look like the following,
    it works fine. No alerts of this type are generated.

    suppress =
    {
        { gid = 122, sid = 1 }
    }

    But if I add an IP source, the configuration doesn't generate any errors,
    but nothing is supressed.

    suppress =
    {
        { gid = 122, sid = 1, track = by_src, ip = '1.2.3.4' }
    }

    Any idea what I am doing wrong?

    Also, as a feature request, would it be useful to be able to supress based
    on a dynamic list, say for example based on the output of a DNS request
    (that could be cached and periodically updated for efficiency)?

    TIA,
    Albert O'Balsam

    _______________________________________________
    Snort-users mailing list
    [email protected]
    Go to this URL to change user options or unsubscribe:
    https://lists.snort.org/mailman/listinfo/snort-users

         To unsubscribe, send an email to:
         [email protected]

    Please visit http://blog.snort.org to stay current on all the latest Snort news!

    Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette


_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

        To unsubscribe, send an email to:
        [email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.