Ruleset advice for beginners

Peter Lyons via Snort-users <[email protected]> Thu, 18 Jun 2026 09:57:12 +1000
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============2790554810807253031==
Content-Type: multipart/alternative;
 boundary="------------GOCk7F77pCFb1j0CyjEd0535"
Content-Language: en-US

This is a multi-part message in MIME format.
--------------GOCk7F77pCFb1j0CyjEd0535
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

About a year ago I installed snort3 and pulledpork on ubuntu 24.04 to 
provide better protection on my home network.


I registered and used the LightSPD_ruleset, rule_mode=simple, 
ips_policy=balanced


Got it all working, and auto updating the LightSPD ruleset everyday.


At the start, I was checking the log $ tail -f /var/snort/alert_json.txt 
to see if it was working.


So I felt very happy and secure.


Then the other day I checked the log file a bit more and noticed the log 
file only had *alert warnings* and no rule actions like block or drop etc.


So then I checked the LightSPD_ruleset and noticed that by default the 
rule actions are all set to *alert warnings.*


Which means I have to monitor the log file and customize the rules myself.


While I’d call myself a linux enthusiast, I don’t have the expertise to 
do that.


*Is there a way to get a rule set suitable for a home network?*


I’m thinking there might be a community rule set suitable or pay for a 
subscribed Talos ruleset.


I’m assuming the subscribed ruleset comes with rule actions to provide 
protection, and instant threat updates.

Are my options correct?


Advise please.

PS: I am new to this mailing list.

Peter Lyons


--------------GOCk7F77pCFb1j0CyjEd0535
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p> </p>
    <p style="line-height: 100%; margin-bottom: 0in">
      About a year ago I installed snort3 and pulledpork on ubuntu 24.04
      to
      provide better protection on my home network.</p>
    <p style="line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style="line-height: 100%; margin-bottom: 0in">I registered and
      used the
      LightSPD_ruleset, rule_mode=simple, ips_policy=balanced</p>
    <p style="line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style="line-height: 100%; margin-bottom: 0in">Got it all working,
      and auto updating the LightSPD ruleset everyday.</p>
    <p style="line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style="line-height: 100%; margin-bottom: 0in">At the start, I was
      checking the log $ tail -f /var/snort/alert_json.txt to see if it
      was
      working.</p>
    <p style="line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style="line-height: 100%; margin-bottom: 0in">So I felt very
      happy
      and secure.</p>
    <p style="line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style="line-height: 100%; margin-bottom: 0in">Then the other day
      I
      checked the log file a bit more and noticed the log file only had
      <b>alert warnings</b> and no rule actions like block or drop etc.</p>
    <p style="line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style="line-height: 100%; margin-bottom: 0in">So then I checked
      the LightSPD_ruleset and noticed that by default the rule actions
      are
      all set to <b>alert warnings.</b></p>
    <p style="line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style="line-height: 100%; margin-bottom: 0in">Which means I have
      to monitor the log file and customize the rules myself.</p>
    <p style="line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style="line-height: 100%; margin-bottom: 0in">While I’d call
      myself a linux enthusiast, I don’t have the expertise to do that.</p>
    <p style="line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style="line-height: 100%; margin-bottom: 0in"><b>Is there a way
        to
        get a rule set suitable for a home network?</b></p>
    <p style="line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style="line-height: 100%; margin-bottom: 0in">I’m thinking there
      might be a community rule set suitable or pay for a subscribed
      Talos
      ruleset.</p>
    <p style="line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style="line-height: 100%; margin-bottom: 0in">I’m assuming the
      subscribed ruleset comes with rule actions to provide protection,
      and
      instant threat updates.</p>
    <p style="line-height: 100%; margin-bottom: 0in"> </p>
    <p style="line-height: 100%; margin-bottom: 0in">Are my options
      correct? </p>
    <p style="line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style="line-height: 100%; margin-bottom: 0in">Advise please.</p>
    <p>
      <style type="text/css">p { line-height: 115%; margin-bottom: 0.1in; background: transparent }</style></p>
    <p>PS: I am new to this mailing list.</p>
    <p>Peter Lyons</p>
    <p><br>
    </p>
  </body>
</html>

--------------GOCk7F77pCFb1j0CyjEd0535--

--===============2790554810807253031==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

--===============2790554810807253031==--