Re: Snort 3 registered ruleset format changes?
Yehor Velykozhon via Snort-users <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <PR3PR05MB71131B6015EE50C3CFFC6726BCD89@PR3PR05MB7113.eurprd05.prod.outlook.com> |
Hi, you should send an email to snort-sigs to get information about your issue. Thanks, Yehor. From: Snort-users <[email protected]> on behalf of Dheeraj Gupta via Snort-users <[email protected]> Date: Wednesday, 8 February 2023, 07:04 To: [email protected] <[email protected]> Subject: [Snort-users] Snort 3 registered ruleset format changes? CAUTION: This email originated from outside the organization. Do not click links or open attachments unless you recognize the sender and know the content is safe. Hi, We have observed that in last two ruleset releases (2-Feb and 6-Feb), the structure of the registered ruleset tar.gz has changed. In the 2-Feb-2023 release (snortrules-snapshot-31470.tar.gz), only so_rules were present and a single rules file was present. In the 6-Feb-2023 release(snortrules-snapshot-31470.tar.gz), the rules folder has two sub-folders (3.0.0.0) and (3.1.35.0). The former has multiple rule files while the latter has single rule file (snort3-file-java.rules) This is problematic for us because the active rule number has suddenly gone down from around 40K to 3K and usual alerts have stopped. Has there been an official change in how rule tar.g are structured or is this a transient bug? I have not looked at Talos-LightSPD so can't comment on its structure Thanks, Dheeraj _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette