Re: Ruleset advice for beginners
stephane Eteme via Snort-users <[email protected]> Fri, 19 Jun 2026 07:14:12 +0100
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <CAJXvT9At+s5GMXJN-93deK5X9nw-P_SQd=Yc7LbPW9VRrX64rw@mail.gmail.com> |
--===============0577508162673334468== Content-Type: multipart/alternative; boundary="000000000000563f79065495347e" --000000000000563f79065495347e Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable You can also try Security Onion Le jeu. 18 juin 2026 =C3=A0 18:43, Alex Tatistcheff via Snort-users < [email protected]> a =C3=A9crit : > Couple of things. > > First, you do have to have Snort installed in inline mode to do any drops > at all. It means two interfaces (outside and inside) and proper > configuration. > > Second, part of the rule text contains the security policy that Talos has > created that determines the rule state (alert, drop, disabled). You'll s= ee > this in the metadata keyword. Look for "policy". You'll see things like > balanced, connectivity, security, max-detect. This is what the rule stat= e > is in the various policies as recommended by Talos. I believe you can us= e > Pulledpork to create your dropsid.conf based on these keywords. So you > could, for example, enable all the rules in the balanced rule set and set > them to drop. > > Hope that helps. > > Alex Tatistcheff > [email protected] > > > > On Thu, Jun 18, 2026 at 9:22=E2=80=AFAM Peter Lyons via Snort-users < > [email protected]> wrote: > >> About a year ago I installed snort3 and pulledpork on ubuntu 24.04 to >> provide better protection on my home network. >> >> >> I registered and used the LightSPD_ruleset, rule_mode=3Dsimple, >> ips_policy=3Dbalanced >> >> >> Got it all working, and auto updating the LightSPD ruleset everyday. >> >> >> At the start, I was checking the log $ tail -f /var/snort/alert_json.txt >> to see if it was working. >> >> >> So I felt very happy and secure. >> >> >> Then the other day I checked the log file a bit more and noticed the log >> file only had *alert warnings* and no rule actions like block or drop >> etc. >> >> >> So then I checked the LightSPD_ruleset and noticed that by default the >> rule actions are all set to *alert warnings.* >> >> >> Which means I have to monitor the log file and customize the rules mysel= f. >> >> >> While I=E2=80=99d call myself a linux enthusiast, I don=E2=80=99t have t= he expertise to >> do that. >> >> >> *Is there a way to get a rule set suitable for a home network?* >> >> >> I=E2=80=99m thinking there might be a community rule set suitable or pay= for a >> subscribed Talos ruleset. >> >> >> I=E2=80=99m assuming the subscribed ruleset comes with rule actions to p= rovide >> protection, and instant threat updates. >> >> Are my options correct? >> >> >> Advise please. >> >> PS: I am new to this mailing list. >> >> Peter Lyons >> >> >> _______________________________________________ >> Snort-users mailing list >> [email protected] >> Go to this URL to change user options or unsubscribe: >> https://lists.snort.org/mailman/listinfo/snort-users >> >> To unsubscribe, send an email to: >> [email protected] >> >> Please visit http://blog.snort.org to stay current on all the latest >> Snort news! >> >> Please follow these rules: >> https://snort.org/faq/what-is-the-mailing-list-etiquette >> > _______________________________________________ > Snort-users mailing list > [email protected] > Go to this URL to change user options or unsubscribe: > https://lists.snort.org/mailman/listinfo/snort-users > > To unsubscribe, send an email to: > [email protected] > > Please visit http://blog.snort.org to stay current on all the latest > Snort news! > > Please follow these rules: > https://snort.org/faq/what-is-the-mailing-list-etiquette > --000000000000563f79065495347e Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"auto">You can also try Security Onion</div><div><br><div class= =3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr= ">Le=C2=A0jeu. 18 juin 2026 =C3=A0 18:43, Alex Tatistcheff via Snort-users = <<a href=3D"mailto:[email protected]">[email protected].= org</a>> a =C3=A9crit=C2=A0:<br></div><blockquote class=3D"gmail_quote" = style=3D"margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:s= olid;padding-left:1ex;border-left-color:rgb(204,204,204)"><div dir=3D"ltr">= <div>Couple of things.</div><div><br></div><div>First, you do have to have = Snort installed in inline mode to do any drops at all.=C2=A0 It means two i= nterfaces (outside and inside) and proper configuration.</div><div><br></di= v><div>Second, part of the rule text contains the security policy that Talo= s has created that determines the rule state (alert, drop, disabled).=C2=A0= You'll see this in the metadata=C2=A0keyword.=C2=A0 Look for "pol= icy".=C2=A0 You'll see things like balanced, connectivity, securit= y, max-detect.=C2=A0 This is what the rule state is in the various=C2=A0pol= icies as recommended by Talos.=C2=A0 I believe you can use Pulledpork=C2=A0= to create your dropsid.conf based on these keywords.=C2=A0 So you could, fo= r example, enable all the rules in the balanced rule set and set them to dr= op.</div><div><br></div><div>Hope that helps.</div><div><br></div><div><div= dir=3D"ltr" class=3D"gmail_signature" data-smartmail=3D"gmail_signature"><= div dir=3D"ltr">Alex Tatistcheff<br><a href=3D"mailto:[email protected]" targ= et=3D"_blank">[email protected]</a><br><div><br></div></div></div></div><br><= /div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">O= n Thu, Jun 18, 2026 at 9:22=E2=80=AFAM Peter Lyons via Snort-users <<a h= ref=3D"mailto:[email protected]" target=3D"_blank">snort-users@li= sts.snort.org</a>> wrote:<br></div><blockquote class=3D"gmail_quote" sty= le=3D"margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:soli= d;padding-left:1ex;border-left-color:rgb(204,204,204)"><u></u> =20 =20 =20 <div> <p> </p> <p style=3D"line-height:100%;margin-bottom:0in"> About a year ago I installed snort3 and pulledpork on ubuntu 24.04 to provide better protection on my home network.</p> <p style=3D"line-height:100%;margin-bottom:0in"><br> </p> <p style=3D"line-height:100%;margin-bottom:0in">I registered and used the LightSPD_ruleset, rule_mode=3Dsimple, ips_policy=3Dbalanced</p> <p style=3D"line-height:100%;margin-bottom:0in"><br> </p> <p style=3D"line-height:100%;margin-bottom:0in">Got it all working, and auto updating the LightSPD ruleset everyday.</p> <p style=3D"line-height:100%;margin-bottom:0in"><br> </p> <p style=3D"line-height:100%;margin-bottom:0in">At the start, I was checking the log $ tail -f /var/snort/alert_json.txt to see if it was working.</p> <p style=3D"line-height:100%;margin-bottom:0in"><br> </p> <p style=3D"line-height:100%;margin-bottom:0in">So I felt very happy and secure.</p> <p style=3D"line-height:100%;margin-bottom:0in"><br> </p> <p style=3D"line-height:100%;margin-bottom:0in">Then the other day I checked the log file a bit more and noticed the log file only had <b>alert warnings</b> and no rule actions like block or drop etc.</p> <p style=3D"line-height:100%;margin-bottom:0in"><br> </p> <p style=3D"line-height:100%;margin-bottom:0in">So then I checked the LightSPD_ruleset and noticed that by default the rule actions are all set to <b>alert warnings.</b></p> <p style=3D"line-height:100%;margin-bottom:0in"><br> </p> <p style=3D"line-height:100%;margin-bottom:0in">Which means I have to monitor the log file and customize the rules myself.</p> <p style=3D"line-height:100%;margin-bottom:0in"><br> </p> <p style=3D"line-height:100%;margin-bottom:0in">While I=E2=80=99d call myself a linux enthusiast, I don=E2=80=99t have the expertise to do t= hat.</p> <p style=3D"line-height:100%;margin-bottom:0in"><br> </p> <p style=3D"line-height:100%;margin-bottom:0in"><b>Is there a way to get a rule set suitable for a home network?</b></p> <p style=3D"line-height:100%;margin-bottom:0in"><br> </p> <p style=3D"line-height:100%;margin-bottom:0in">I=E2=80=99m thinking th= ere might be a community rule set suitable or pay for a subscribed Talos ruleset.</p> <p style=3D"line-height:100%;margin-bottom:0in"><br> </p> <p style=3D"line-height:100%;margin-bottom:0in">I=E2=80=99m assuming th= e subscribed ruleset comes with rule actions to provide protection, and instant threat updates.</p> <p style=3D"line-height:100%;margin-bottom:0in"> </p> <p style=3D"line-height:100%;margin-bottom:0in">Are my options correct? </p> <p style=3D"line-height:100%;margin-bottom:0in"><br> </p> <p style=3D"line-height:100%;margin-bottom:0in">Advise please.</p> <p> </p> <p>PS: I am new to this mailing list.</p> <p>Peter Lyons</p> <p><br> </p> </div> _______________________________________________<br> Snort-users mailing list<br> <a href=3D"mailto:[email protected]" target=3D"_blank">Snort-user= [email protected]</a><br> Go to this URL to change user options or unsubscribe:<br> <a href=3D"https://lists.snort.org/mailman/listinfo/snort-users" rel=3D"nor= eferrer" target=3D"_blank">https://lists.snort.org/mailman/listinfo/snort-u= sers</a><br> <br> =C2=A0 =C2=A0 =C2=A0 =C2=A0 To unsubscribe, send an email to:<br> =C2=A0 =C2=A0 =C2=A0 =C2=A0 <a href=3D"mailto:[email protected]= .org" target=3D"_blank">[email protected]</a><br> <br> Please visit <a href=3D"http://blog.snort.org" rel=3D"noreferrer" target=3D= "_blank">http://blog.snort.org</a> to stay current on all the latest Snort = news!<br> <br> Please follow these rules: <a href=3D"https://snort.org/faq/what-is-the-mai= ling-list-etiquette" rel=3D"noreferrer" target=3D"_blank">https://snort.org= /faq/what-is-the-mailing-list-etiquette</a><br> </blockquote></div> _______________________________________________<br> Snort-users mailing list<br> <a href=3D"mailto:[email protected]" target=3D"_blank">Snort-user= [email protected]</a><br> Go to this URL to change user options or unsubscribe:<br> <a href=3D"https://lists.snort.org/mailman/listinfo/snort-users" rel=3D"nor= eferrer" target=3D"_blank">https://lists.snort.org/mailman/listinfo/snort-u= sers</a><br> <br> =C2=A0 =C2=A0 =C2=A0 =C2=A0 To unsubscribe, send an email to:<br> =C2=A0 =C2=A0 =C2=A0 =C2=A0 <a href=3D"mailto:[email protected]= .org" target=3D"_blank">[email protected]</a><br> <br> Please visit <a href=3D"http://blog.snort.org" rel=3D"noreferrer" target=3D= "_blank">http://blog.snort.org</a> to stay current on all the latest Snort = news!<br> <br> Please follow these rules: <a href=3D"https://snort.org/faq/what-is-the-mai= ling-list-etiquette" rel=3D"noreferrer" target=3D"_blank">https://snort.org= /faq/what-is-the-mailing-list-etiquette</a><br> </blockquote></div></div> --000000000000563f79065495347e-- --===============0577508162673334468== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette --===============0577508162673334468==--