Re: Using LightSPD rules when we have custom config
"Brendan Bell \(brebell\) via Snort-users" <[email protected]> Wed, 14 Aug 2024 12:42:53 +0000
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <DM6PR11MB4737F98CC9506D33830B6F48B2872@DM6PR11MB4737.namprd11.prod.outlook.com> |
Dheeraj, Hello and thank you for your question. I'll be in touch this week with a specific answer. Brendan ________________________________ From: Snort-users <[email protected]> on behalf of Dheeraj Gupta via Snort-users <[email protected]> Sent: Wednesday, August 14, 2024 3:23 AM To: [email protected] <[email protected]> Subject: [Snort-users] Using LightSPD rules when we have custom config Hi, I have been trying to understand usage of LightSPD rules in order to switch to using them. I had earlier too posted on the same topic in this mailing-list ( https://seclists.org/snort/2024/q1/44 ). My understanding now is that in order to use the LightSPD rules, we do the following: - Find out our snort version (V1) - Unzip the LightSPD tarball and open manifest.json. Then lookup the latest version entry <= V1 - Specify architectures -> YOUR_ARCH -> modules_path to --plugin-path switch in snort command - Specify policies_path/POLICY_NAME.lua as value to -c switch in snort command line However, we have some customized configuration in our environment (afpacket daq, perf_monitor, alert_json, home_net, port spec etc) which we would like to reuse when updating rules. What is the standard procedure when using LightSPD with custom configuration? I would not like to specify all configuration options in command line but use lua files for the same - Do we define our own config file and keep an include() which is updated with appropriate policy based on LightSPD at every update? or can we use command line switches to specify base and custom policy files? - How can we disable certain rules (in pulledpork we can update disablesid.conf) or enable or modify the rules when deploying rule updates? Would this be done in our lua config and can we use rule sids or gids directly to enable/disable? - Is there a standard tool (something like pulledpork) which can automate extraction of paths from manifest? Regards, Dheeraj _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette