Fialed to download registered rules (release 3.1.59.0)
Carlos Lopez via Snort-users <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <PRAP251MB056748AFAEB9D513313C1D3FDB9B9@PRAP251MB0567.EURP251.PROD.OUTLOOK.COM> |
Hi all,
I have just setup a FreeBSD 13.2 with Snort 3.1.59.0 and when I try to download registered rules with pulledpork3, the following error appears:
Entering: Config.validate()
Exiting: Config.validate()
Setting up the working directory structure in: /tmp/PulledPork-2023.04.12-14.12.25
- Successfully setup the working directory
Working directory is: WorkingDirectory(path:/tmp/PulledPork-2023.04.12-14.12.25, cleanup_on_exit:True)
Determining Snort version from executable
- Running Snort using: snort -V
- Output from Snort:
b'\n ,,_ -*> Snort++ <*-\n o" )~ Version 3.1.59.0\n \'\'\'\' By Martin Roesch & The Snort Team\n http://snort.org/contact#team\n Copyright (C) 2014-2023 Cisco and/or its affiliates. All rights reserved.\n Copyright (C) 1998-2013 Sourcefire, Inc., et al.\n Using DAQ version 3.0.11\n Using LuaJIT version 2.1.0-beta3\n Using OpenSSL 1.1.1t-freebsd 7 Feb 2023\n Using libpcap version 1.9.1\n Using PCRE version 8.45 2021-06-15\n Using ZLIB version 1.2.13\n Using Hyperscan version 5.4.0 2023-02-19\n Using LZMA version 5.4.1\n\n'
- Snort version is: 3.1.59.0
---------------------------------
After parsing the command line and configuration file, this is what I know:
Program will terminate when encountering an error or warning.
Oinkcode will be obfuscated in the output (this is a good thing).
Temporary directory is: /tmp
Temporary working directory will be deleted at the end.
The Snort version number used for processing is: 3.1.59.0
The distro used for processing is: ubuntu-x64
The ips policy used for processing is: balanced
Pre-compiled (.so) rules will not be processed.
Rulesets will be downloaded from:
Snort Registered Ruleset
The following rules files will not be included in rulesets: includes.rules, snort3-deleted.rules
Rule Output mode is: simple
Rules from Local rules file will be included: /usr/local/etc/snort/rules/local.rules
All Rules will be written to a single file: /usr/local/etc/snort/rules/pulledpork.rules
Disabled rules will not be written to the rules file
The rule_mode is: simple
No Blocklists will be downloaded.
The state_order is: ['enable', 'drop', 'disable']
Snort will NOT be reloaded with new configuration.
---------------------------------
Loading rulesets
Downloading Snort rulesets from Internet
Loading rules archive:
- Source: https://snort.org/rules/snortrules-snapshot-31590.tar.gz
WARNING: Unable to load rules archive: 422 Client Error: Unprocessable Entity for url: https://snort.org/rules/snortrules-snapshot-31590.tar.gz?oinkcode=<hidden>
---------------------------------
Attempting to delete working directory: /tmp/PulledPork-2023.04.12-14.12.25
- Successfully deleted working directory
Which it is correct .... There is no rules for 3.1.59.0 release in Snort Rules and IDS Software Download<https://www.snort.org/downloads#rules> ... Do I need to download community rules or rules for 3.1.47.0 version?
Regards,
C. L. Martinez
_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users
To unsubscribe, send an email to:
[email protected]
Please visit http://blog.snort.org to stay current on all the latest Snort news!
Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette