Re: Ruleset advice for beginners

Jonathan Lee via Snort-users <[email protected]> Thu, 18 Jun 2026 09:07:02 -0700
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <[email protected]>
--===============8766344431510465005==
Content-Type: multipart/alternative; boundary=Apple-Mail-9812D02C-1250-4D5D-9D78-77A699BAFA74
Content-Transfer-Encoding: 7bit


--Apple-Mail-9812D02C-1250-4D5D-9D78-77A699BAFA74
Content-Type: text/plain;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

You have to set block on alert and inline mode or legacy mode=20
Sent from my iPhone

> On Jun 18, 2026, at 08:50, Peter Lyons via Snort-users <snort-users@lists.=
snort.org> wrote:
>=20
> =EF=BB=BF
> About a year ago I installed snort3 and pulledpork on ubuntu 24.04 to prov=
ide better protection on my home network.
>=20
> I registered and used the LightSPD_ruleset, rule_mode=3Dsimple, ips_policy=
=3Dbalanced
>=20
> Got it all working, and auto updating the LightSPD ruleset everyday.
>=20
> At the start, I was checking the log $ tail -f /var/snort/alert_json.txt t=
o see if it was working.
>=20
> So I felt very happy and secure.
>=20
> Then the other day I checked the log file a bit more and noticed the log f=
ile only had alert warnings and no rule actions like block or drop etc.
>=20
> So then I checked the LightSPD_ruleset and noticed that by default the rul=
e actions are all set to alert warnings.
>=20
> Which means I have to monitor the log file and customize the rules myself.=

>=20
> While I=E2=80=99d call myself a linux enthusiast, I don=E2=80=99t have the=
 expertise to do that.
>=20
> Is there a way to get a rule set suitable for a home network?
>=20
> I=E2=80=99m thinking there might be a community rule set suitable or pay f=
or a subscribed Talos ruleset.
>=20
> I=E2=80=99m assuming the subscribed ruleset comes with rule actions to pro=
vide protection, and instant threat updates.
> Are my options correct?
>=20
> Advise please.
> PS: I am new to this mailing list.
>=20
> Peter Lyons
>=20
>=20
>=20
> _______________________________________________
> Snort-users mailing list
> [email protected]
> Go to this URL to change user options or unsubscribe:
> https://lists.snort.org/mailman/listinfo/snort-users
>=20
>    To unsubscribe, send an email to:
>    [email protected]
>=20
> Please visit http://blog.snort.org to stay current on all the latest Snort=
 news!
>=20
> Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-=
etiquette

--Apple-Mail-9812D02C-1250-4D5D-9D78-77A699BAFA74
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html class=3D"apple-mail-supports-explicit-dark-mode"><head><meta http-equi=
v=3D"content-type" content=3D"text/html; charset=3Dutf-8"></head><body dir=3D=
"auto">You have to set block on alert and inline mode or legacy mode&nbsp;<b=
r id=3D"lineBreakAtBeginningOfSignature"><div dir=3D"ltr">Sent from my iPhon=
e</div><div dir=3D"ltr"><br><blockquote type=3D"cite">On Jun 18, 2026, at 08=
:50, Peter Lyons via Snort-users &lt;[email protected]&gt; wrote:<=
br><br></blockquote></div><blockquote type=3D"cite"><div dir=3D"ltr">=EF=BB=BF=


 =20

    <meta http-equiv=3D"content-type" content=3D"text/html; charset=3DUTF-8"=
>
 =20
 =20
    <p> </p>
    <p style=3D"line-height: 100%; margin-bottom: 0in">
      About a year ago I installed snort3 and pulledpork on ubuntu 24.04
      to
      provide better protection on my home network.</p>
    <p style=3D"line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style=3D"line-height: 100%; margin-bottom: 0in">I registered and
      used the
      LightSPD_ruleset, rule_mode=3Dsimple, ips_policy=3Dbalanced</p>
    <p style=3D"line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style=3D"line-height: 100%; margin-bottom: 0in">Got it all working,
      and auto updating the LightSPD ruleset everyday.</p>
    <p style=3D"line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style=3D"line-height: 100%; margin-bottom: 0in">At the start, I was
      checking the log $ tail -f /var/snort/alert_json.txt to see if it
      was
      working.</p>
    <p style=3D"line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style=3D"line-height: 100%; margin-bottom: 0in">So I felt very
      happy
      and secure.</p>
    <p style=3D"line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style=3D"line-height: 100%; margin-bottom: 0in">Then the other day
      I
      checked the log file a bit more and noticed the log file only had
      <b>alert warnings</b> and no rule actions like block or drop etc.</p>
    <p style=3D"line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style=3D"line-height: 100%; margin-bottom: 0in">So then I checked
      the LightSPD_ruleset and noticed that by default the rule actions
      are
      all set to <b>alert warnings.</b></p>
    <p style=3D"line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style=3D"line-height: 100%; margin-bottom: 0in">Which means I have
      to monitor the log file and customize the rules myself.</p>
    <p style=3D"line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style=3D"line-height: 100%; margin-bottom: 0in">While I=E2=80=99d cal=
l
      myself a linux enthusiast, I don=E2=80=99t have the expertise to do th=
at.</p>
    <p style=3D"line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style=3D"line-height: 100%; margin-bottom: 0in"><b>Is there a way
        to
        get a rule set suitable for a home network?</b></p>
    <p style=3D"line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style=3D"line-height: 100%; margin-bottom: 0in">I=E2=80=99m thinking t=
here
      might be a community rule set suitable or pay for a subscribed
      Talos
      ruleset.</p>
    <p style=3D"line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style=3D"line-height: 100%; margin-bottom: 0in">I=E2=80=99m assuming t=
he
      subscribed ruleset comes with rule actions to provide protection,
      and
      instant threat updates.</p>
    <p style=3D"line-height: 100%; margin-bottom: 0in"> </p>
    <p style=3D"line-height: 100%; margin-bottom: 0in">Are my options
      correct? </p>
    <p style=3D"line-height: 100%; margin-bottom: 0in"><br>
    </p>
    <p style=3D"line-height: 100%; margin-bottom: 0in">Advise please.</p>
    <p>
      </p>
    <p>PS: I am new to this mailing list.</p>
    <p>Peter Lyons</p>
    <p><br>
    </p>
 =20

<span>_______________________________________________</span><br><span>Snort-=
users mailing list</span><br><span>[email protected]</span><br><sp=
an>Go to this URL to change user options or unsubscribe:</span><br><span>htt=
ps://lists.snort.org/mailman/listinfo/snort-users</span><br><span></span><br=
><span> &nbsp; &nbsp;To unsubscribe, send an email to:</span><br><span> &nbs=
p; &nbsp;[email protected]</span><br><span></span><br><span>=
Please visit http://blog.snort.org to stay current on all the latest Snort n=
ews!</span><br><span></span><br><span>Please follow these rules: https://sno=
rt.org/faq/what-is-the-mailing-list-etiquette</span><br></div></blockquote><=
/body></html>=

--Apple-Mail-9812D02C-1250-4D5D-9D78-77A699BAFA74--

--===============8766344431510465005==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

--===============8766344431510465005==--