Re: Snort3: checking rules syntax
Meridoff via Snort-users <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <CAFfuDwxm6MwOYsu7cZbq0qBzLMCxBPM8SBsdhT-mv0XOGkg7UQ@mail.gmail.com> |
Thanks! I knew this option but it confused me because it doesn't show any error messages about buggy rules, it shows only the wrong line in config (if it has one). It only shows status code, but no information about what rule is buggy. But when we run Snort in the usual way (without -T) with a wrong rule - we can see in a log what rule is wrong and some info of this wrong rule. Is it possible to see in test mode (-T) information about what rule is wrong ? ср, 27 апр. 2022 г. в 22:42, Joel Esler <[email protected]>: > Check into “-T”. Test mode. > > > On Apr 27, 2022, at 3:30 PM, Meridoff via Snort-users < > [email protected]> wrote: > > > > Hello,is it possible to check rules for syntax before running Snort? > > Or, for example, dry run snort with exist status code. > > > > Thanks > > > > _______________________________________________ > > Snort-users mailing list > > [email protected] > > Go to this URL to change user options or unsubscribe: > > https://lists.snort.org/mailman/listinfo/snort-users > > > > To unsubscribe, send an email to: > > [email protected] > > > > Please visit http://blog.snort.org to stay current on all the latest > Snort news! > > > > Please follow these rules: > https://snort.org/faq/what-is-the-mailing-list-etiquette > > _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette