Error in registered TalosLightSPD ruleset released on 2026-03-24?
Dheeraj Gupta via Snort-users <[email protected]> Thu, 26 Mar 2026 13:56:49 +0530
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <CAOsL98Pgq7Z7nqRoVEmsPdW2qqNgjfYEXHesifLiBOapG4YoWA@mail.gmail.com> |
--===============0641982091904660207==
Content-Type: multipart/alternative; boundary="0000000000000e9ee7064de92600"
--0000000000000e9ee7064de92600
Content-Type: text/plain; charset="UTF-8"
Hi,
We are using registered ruleset for Snort. After downloading the latest
LightSPD ruleset released on 2026-03-24, our sensor failed to start up with
an error
ERROR: ips.rules:6 can't open ../../rules/3.1.25.0/includes.rules
ERROR: ips.states:6 can't open ../../rules/
3.1.25.0/rulestates-security-ips.states
Looking at the the file lightspd/policies/common/load_ips.lua in the
release, there is a reference to 3.1.25 (which was not there in older
release)
if TALOS.functions.minsnortver_str("3.1.25.0-0") then
table.insert(ruleDirs, "../../rules/3.1.25.0")
end
while there is no 3.1.25.0 subdirectory in the rules/
Commenting out the above 3 lines allows sensor to start. Is this a problem
with only the registered ruleset?
I initially posted this in snort-sigs list but cross-posting here as no
response was received on that list
Thanks,
Dheeraj
--0000000000000e9ee7064de92600
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
<div dir=3D"ltr"><div class=3D"gmail_quote gmail_quote_container"><div dir=
=3D"ltr"><div dir=3D"ltr"><div>Hi,</div><div><br></div><div>We are using re=
gistered
ruleset for Snort. After downloading the latest LightSPD ruleset=20
released on 2026-03-24, our sensor failed to start up with an error</div><d=
iv><br></div><div>ERROR: ips.rules:6 can't open ../../rules/<a href=3D"=
http://3.1.25.0/includes.rules" target=3D"_blank">3.1.25.0/includes.rules</=
a><br>ERROR: ips.states:6 can't open ../../rules/<a href=3D"http://3.1.=
25.0/rulestates-security-ips.states" target=3D"_blank">3.1.25.0/rulestates-=
security-ips.states</a></div><div><br></div><div>Looking at the the file=C2=
=A0lightspd/policies/common/load_ips.lua in the release, there is a referen=
ce to 3.1.25 (which was not there in older release)</div><div><br></div><di=
v>if TALOS.functions.minsnortver_str("3.1.25.0-0") then<br>=C2=A0=
=C2=A0table.insert(ruleDirs, "../../rules/<a href=3D"http://3.1.25.0"=
target=3D"_blank">3.1.25.0</a>")<br>end</div><div><br></div><div>whil=
e there is no 3.1.25.0 subdirectory in the rules/</div><div><br></div><div>=
Commenting out the above 3 lines allows sensor to start. Is this a problem =
with only the registered ruleset?</div><div><br></div><div>I initially post=
ed this in snort-sigs list but cross-posting here as no response was receiv=
ed on that list</div><div><br></div><div>Thanks,</div><div>Dheeraj</div></d=
iv><br></div>
</div></div>
--0000000000000e9ee7064de92600--
--===============0641982091904660207==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users
To unsubscribe, send an email to:
[email protected]
Please visit http://blog.snort.org to stay current on all the latest Snort news!
Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
--===============0641982091904660207==--