Re: Snort3: checking rules syntax
Meridoff via Snort-users <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <CAFfuDwyPrT0O8RQrHHCG1yD3SSsNckMMGSTCL4ghnyevLyhqOg@mail.gmail.com> |
No it did not. You can check it. I run snort in non-daemon mode with -v (verbose) and -T , and config included wrong rule. No information about rule mistake was printed.. чт, 28 апр. 2022 г., 18:16 Joel Esler <[email protected]>: > https://www.snort.org/faq/what-is-the-mailing-list-etiquette > > Rule Number 5. > > On Apr 28, 2022, at 6:02 AM, Meridoff <[email protected]> wrote: > > No it did not. You can check it. > I run snort in non-daemon mode with -v (verbose) and -T > > чт, 28 апр. 2022 г., 04:00 Joel Esler <[email protected]>: > >> The config Includes the rule files. So if there is a rule that has an >> error, Snort will tell you which line in the rule file has the error. >> >> — >> Sent from my iPhone >> >> On Apr 27, 2022, at 18:01, Meridoff <[email protected]> wrote: >> >> >> Thanks! >> I knew this option but it confused me because it doesn't show any error >> messages about buggy rules, it shows only the wrong line in config (if it >> has one). >> >> It only shows status code, but no information about what rule is buggy. >> But when we run Snort in the usual way (without -T) with a wrong rule - >> we can see in a log what rule is wrong and some info of this wrong rule. >> >> Is it possible to see in test mode (-T) information about what rule is >> wrong ? >> >> ср, 27 апр. 2022 г. в 22:42, Joel Esler <[email protected]>: >> >>> Check into “-T”. Test mode. >>> >>> > On Apr 27, 2022, at 3:30 PM, Meridoff via Snort-users < >>> [email protected]> wrote: >>> > >>> > Hello,is it possible to check rules for syntax before running Snort? >>> > Or, for example, dry run snort with exist status code. >>> > >>> > Thanks >>> > >>> > _______________________________________________ >>> > Snort-users mailing list >>> > [email protected] >>> > Go to this URL to change user options or unsubscribe: >>> > https://lists.snort.org/mailman/listinfo/snort-users >>> > >>> > To unsubscribe, send an email to: >>> > [email protected] >>> > >>> > Please visit http://blog.snort.org to stay current on all the latest >>> Snort news! >>> > >>> > Please follow these rules: >>> https://snort.org/faq/what-is-the-mailing-list-etiquette >>> >>> > _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette