Fialed to download registered rules (release 3.1.59.0)

Carlos Lopez via Snort-users <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <PRAP251MB056748AFAEB9D513313C1D3FDB9B9@PRAP251MB0567.EURP251.PROD.OUTLOOK.COM>
Hi all,

I have just setup a FreeBSD 13.2 with Snort 3.1.59.0 and when I try to download registered rules with pulledpork3, the following error appears:

Entering: Config.validate()
Exiting: Config.validate()
Setting up the working directory structure in: /tmp/PulledPork-2023.04.12-14.12.25
- Successfully setup the working directory
Working directory is:  WorkingDirectory(path:/tmp/PulledPork-2023.04.12-14.12.25, cleanup_on_exit:True)
Determining Snort version from executable
- Running Snort using:  snort -V
- Output from Snort:
b'\n   ,,_     -*> Snort++ <*-\n  o"  )~   Version 3.1.59.0\n   \'\'\'\'    By Martin Roesch & The Snort Team\n           http://snort.org/contact#team\n           Copyright (C) 2014-2023 Cisco and/or its affiliates. All rights reserved.\n           Copyright (C) 1998-2013 Sourcefire, Inc., et al.\n           Using DAQ version 3.0.11\n           Using LuaJIT version 2.1.0-beta3\n           Using OpenSSL 1.1.1t-freebsd  7 Feb 2023\n           Using libpcap version 1.9.1\n           Using PCRE version 8.45 2021-06-15\n           Using ZLIB version 1.2.13\n           Using Hyperscan version 5.4.0 2023-02-19\n           Using LZMA version 5.4.1\n\n'
- Snort version is: 3.1.59.0
---------------------------------
After parsing the command line and configuration file, this is what I know:
Program will terminate when encountering an error or warning.
Oinkcode will be obfuscated in the output (this is a good thing).
Temporary directory is:  /tmp
Temporary working directory will be deleted at the end.
The Snort version number used for processing is:  3.1.59.0
The distro used for processing is:  ubuntu-x64
The ips policy used for processing is:  balanced
Pre-compiled (.so) rules will not be processed.
Rulesets will be downloaded from:
        Snort Registered Ruleset
The following rules files will not be included in rulesets:  includes.rules, snort3-deleted.rules
Rule Output mode is:  simple
Rules from Local rules file will be included:  /usr/local/etc/snort/rules/local.rules
All Rules will be written to a single file:  /usr/local/etc/snort/rules/pulledpork.rules
Disabled rules will not be written to the rules file
The rule_mode is:  simple
No Blocklists will be downloaded.
The state_order is: ['enable', 'drop', 'disable']
Snort will NOT be reloaded with new configuration.
---------------------------------
Loading rulesets
Downloading Snort rulesets from Internet
Loading rules archive:
- Source:  https://snort.org/rules/snortrules-snapshot-31590.tar.gz
WARNING: Unable to load rules archive:  422 Client Error: Unprocessable Entity for url: https://snort.org/rules/snortrules-snapshot-31590.tar.gz?oinkcode=<hidden>
---------------------------------
Attempting to delete working directory: /tmp/PulledPork-2023.04.12-14.12.25
- Successfully deleted working directory

Which it is correct .... There is no rules for 3.1.59.0 release in Snort Rules and IDS Software Download<https://www.snort.org/downloads#rules> ... Do I need to download community rules or rules for 3.1.47.0 version?

Regards,
C. L. Martinez

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.