Ruleset advice for beginners
Peter Lyons via Snort-users <[email protected]> Thu, 18 Jun 2026 09:57:12 +1000
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format.
--===============2790554810807253031==
Content-Type: multipart/alternative;
boundary="------------GOCk7F77pCFb1j0CyjEd0535"
Content-Language: en-US
This is a multi-part message in MIME format.
--------------GOCk7F77pCFb1j0CyjEd0535
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
About a year ago I installed snort3 and pulledpork on ubuntu 24.04 to
provide better protection on my home network.
I registered and used the LightSPD_ruleset, rule_mode=simple,
ips_policy=balanced
Got it all working, and auto updating the LightSPD ruleset everyday.
At the start, I was checking the log $ tail -f /var/snort/alert_json.txt
to see if it was working.
So I felt very happy and secure.
Then the other day I checked the log file a bit more and noticed the log
file only had *alert warnings* and no rule actions like block or drop etc.
So then I checked the LightSPD_ruleset and noticed that by default the
rule actions are all set to *alert warnings.*
Which means I have to monitor the log file and customize the rules myself.
While I’d call myself a linux enthusiast, I don’t have the expertise to
do that.
*Is there a way to get a rule set suitable for a home network?*
I’m thinking there might be a community rule set suitable or pay for a
subscribed Talos ruleset.
I’m assuming the subscribed ruleset comes with rule actions to provide
protection, and instant threat updates.
Are my options correct?
Advise please.
PS: I am new to this mailing list.
Peter Lyons
--------------GOCk7F77pCFb1j0CyjEd0535
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
</head>
<body>
<p> </p>
<p style="line-height: 100%; margin-bottom: 0in">
About a year ago I installed snort3 and pulledpork on ubuntu 24.04
to
provide better protection on my home network.</p>
<p style="line-height: 100%; margin-bottom: 0in"><br>
</p>
<p style="line-height: 100%; margin-bottom: 0in">I registered and
used the
LightSPD_ruleset, rule_mode=simple, ips_policy=balanced</p>
<p style="line-height: 100%; margin-bottom: 0in"><br>
</p>
<p style="line-height: 100%; margin-bottom: 0in">Got it all working,
and auto updating the LightSPD ruleset everyday.</p>
<p style="line-height: 100%; margin-bottom: 0in"><br>
</p>
<p style="line-height: 100%; margin-bottom: 0in">At the start, I was
checking the log $ tail -f /var/snort/alert_json.txt to see if it
was
working.</p>
<p style="line-height: 100%; margin-bottom: 0in"><br>
</p>
<p style="line-height: 100%; margin-bottom: 0in">So I felt very
happy
and secure.</p>
<p style="line-height: 100%; margin-bottom: 0in"><br>
</p>
<p style="line-height: 100%; margin-bottom: 0in">Then the other day
I
checked the log file a bit more and noticed the log file only had
<b>alert warnings</b> and no rule actions like block or drop etc.</p>
<p style="line-height: 100%; margin-bottom: 0in"><br>
</p>
<p style="line-height: 100%; margin-bottom: 0in">So then I checked
the LightSPD_ruleset and noticed that by default the rule actions
are
all set to <b>alert warnings.</b></p>
<p style="line-height: 100%; margin-bottom: 0in"><br>
</p>
<p style="line-height: 100%; margin-bottom: 0in">Which means I have
to monitor the log file and customize the rules myself.</p>
<p style="line-height: 100%; margin-bottom: 0in"><br>
</p>
<p style="line-height: 100%; margin-bottom: 0in">While I’d call
myself a linux enthusiast, I don’t have the expertise to do that.</p>
<p style="line-height: 100%; margin-bottom: 0in"><br>
</p>
<p style="line-height: 100%; margin-bottom: 0in"><b>Is there a way
to
get a rule set suitable for a home network?</b></p>
<p style="line-height: 100%; margin-bottom: 0in"><br>
</p>
<p style="line-height: 100%; margin-bottom: 0in">I’m thinking there
might be a community rule set suitable or pay for a subscribed
Talos
ruleset.</p>
<p style="line-height: 100%; margin-bottom: 0in"><br>
</p>
<p style="line-height: 100%; margin-bottom: 0in">I’m assuming the
subscribed ruleset comes with rule actions to provide protection,
and
instant threat updates.</p>
<p style="line-height: 100%; margin-bottom: 0in"> </p>
<p style="line-height: 100%; margin-bottom: 0in">Are my options
correct? </p>
<p style="line-height: 100%; margin-bottom: 0in"><br>
</p>
<p style="line-height: 100%; margin-bottom: 0in">Advise please.</p>
<p>
<style type="text/css">p { line-height: 115%; margin-bottom: 0.1in; background: transparent }</style></p>
<p>PS: I am new to this mailing list.</p>
<p>Peter Lyons</p>
<p><br>
</p>
</body>
</html>
--------------GOCk7F77pCFb1j0CyjEd0535--
--===============2790554810807253031==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users
To unsubscribe, send an email to:
[email protected]
Please visit http://blog.snort.org to stay current on all the latest Snort news!
Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
--===============2790554810807253031==--