Re: Ruleset advice for beginners
Jonathan Lee via Snort-users <[email protected]> Thu, 18 Jun 2026 09:07:02 -0700
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
--===============8766344431510465005== Content-Type: multipart/alternative; boundary=Apple-Mail-9812D02C-1250-4D5D-9D78-77A699BAFA74 Content-Transfer-Encoding: 7bit --Apple-Mail-9812D02C-1250-4D5D-9D78-77A699BAFA74 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable You have to set block on alert and inline mode or legacy mode=20 Sent from my iPhone > On Jun 18, 2026, at 08:50, Peter Lyons via Snort-users <snort-users@lists.= snort.org> wrote: >=20 > =EF=BB=BF > About a year ago I installed snort3 and pulledpork on ubuntu 24.04 to prov= ide better protection on my home network. >=20 > I registered and used the LightSPD_ruleset, rule_mode=3Dsimple, ips_policy= =3Dbalanced >=20 > Got it all working, and auto updating the LightSPD ruleset everyday. >=20 > At the start, I was checking the log $ tail -f /var/snort/alert_json.txt t= o see if it was working. >=20 > So I felt very happy and secure. >=20 > Then the other day I checked the log file a bit more and noticed the log f= ile only had alert warnings and no rule actions like block or drop etc. >=20 > So then I checked the LightSPD_ruleset and noticed that by default the rul= e actions are all set to alert warnings. >=20 > Which means I have to monitor the log file and customize the rules myself.= >=20 > While I=E2=80=99d call myself a linux enthusiast, I don=E2=80=99t have the= expertise to do that. >=20 > Is there a way to get a rule set suitable for a home network? >=20 > I=E2=80=99m thinking there might be a community rule set suitable or pay f= or a subscribed Talos ruleset. >=20 > I=E2=80=99m assuming the subscribed ruleset comes with rule actions to pro= vide protection, and instant threat updates. > Are my options correct? >=20 > Advise please. > PS: I am new to this mailing list. >=20 > Peter Lyons >=20 >=20 >=20 > _______________________________________________ > Snort-users mailing list > [email protected] > Go to this URL to change user options or unsubscribe: > https://lists.snort.org/mailman/listinfo/snort-users >=20 > To unsubscribe, send an email to: > [email protected] >=20 > Please visit http://blog.snort.org to stay current on all the latest Snort= news! >=20 > Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-= etiquette --Apple-Mail-9812D02C-1250-4D5D-9D78-77A699BAFA74 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <html class=3D"apple-mail-supports-explicit-dark-mode"><head><meta http-equi= v=3D"content-type" content=3D"text/html; charset=3Dutf-8"></head><body dir=3D= "auto">You have to set block on alert and inline mode or legacy mode <b= r id=3D"lineBreakAtBeginningOfSignature"><div dir=3D"ltr">Sent from my iPhon= e</div><div dir=3D"ltr"><br><blockquote type=3D"cite">On Jun 18, 2026, at 08= :50, Peter Lyons via Snort-users <[email protected]> wrote:<= br><br></blockquote></div><blockquote type=3D"cite"><div dir=3D"ltr">=EF=BB=BF= =20 <meta http-equiv=3D"content-type" content=3D"text/html; charset=3DUTF-8"= > =20 =20 <p> </p> <p style=3D"line-height: 100%; margin-bottom: 0in"> About a year ago I installed snort3 and pulledpork on ubuntu 24.04 to provide better protection on my home network.</p> <p style=3D"line-height: 100%; margin-bottom: 0in"><br> </p> <p style=3D"line-height: 100%; margin-bottom: 0in">I registered and used the LightSPD_ruleset, rule_mode=3Dsimple, ips_policy=3Dbalanced</p> <p style=3D"line-height: 100%; margin-bottom: 0in"><br> </p> <p style=3D"line-height: 100%; margin-bottom: 0in">Got it all working, and auto updating the LightSPD ruleset everyday.</p> <p style=3D"line-height: 100%; margin-bottom: 0in"><br> </p> <p style=3D"line-height: 100%; margin-bottom: 0in">At the start, I was checking the log $ tail -f /var/snort/alert_json.txt to see if it was working.</p> <p style=3D"line-height: 100%; margin-bottom: 0in"><br> </p> <p style=3D"line-height: 100%; margin-bottom: 0in">So I felt very happy and secure.</p> <p style=3D"line-height: 100%; margin-bottom: 0in"><br> </p> <p style=3D"line-height: 100%; margin-bottom: 0in">Then the other day I checked the log file a bit more and noticed the log file only had <b>alert warnings</b> and no rule actions like block or drop etc.</p> <p style=3D"line-height: 100%; margin-bottom: 0in"><br> </p> <p style=3D"line-height: 100%; margin-bottom: 0in">So then I checked the LightSPD_ruleset and noticed that by default the rule actions are all set to <b>alert warnings.</b></p> <p style=3D"line-height: 100%; margin-bottom: 0in"><br> </p> <p style=3D"line-height: 100%; margin-bottom: 0in">Which means I have to monitor the log file and customize the rules myself.</p> <p style=3D"line-height: 100%; margin-bottom: 0in"><br> </p> <p style=3D"line-height: 100%; margin-bottom: 0in">While I=E2=80=99d cal= l myself a linux enthusiast, I don=E2=80=99t have the expertise to do th= at.</p> <p style=3D"line-height: 100%; margin-bottom: 0in"><br> </p> <p style=3D"line-height: 100%; margin-bottom: 0in"><b>Is there a way to get a rule set suitable for a home network?</b></p> <p style=3D"line-height: 100%; margin-bottom: 0in"><br> </p> <p style=3D"line-height: 100%; margin-bottom: 0in">I=E2=80=99m thinking t= here might be a community rule set suitable or pay for a subscribed Talos ruleset.</p> <p style=3D"line-height: 100%; margin-bottom: 0in"><br> </p> <p style=3D"line-height: 100%; margin-bottom: 0in">I=E2=80=99m assuming t= he subscribed ruleset comes with rule actions to provide protection, and instant threat updates.</p> <p style=3D"line-height: 100%; margin-bottom: 0in"> </p> <p style=3D"line-height: 100%; margin-bottom: 0in">Are my options correct? </p> <p style=3D"line-height: 100%; margin-bottom: 0in"><br> </p> <p style=3D"line-height: 100%; margin-bottom: 0in">Advise please.</p> <p> </p> <p>PS: I am new to this mailing list.</p> <p>Peter Lyons</p> <p><br> </p> =20 <span>_______________________________________________</span><br><span>Snort-= users mailing list</span><br><span>[email protected]</span><br><sp= an>Go to this URL to change user options or unsubscribe:</span><br><span>htt= ps://lists.snort.org/mailman/listinfo/snort-users</span><br><span></span><br= ><span> To unsubscribe, send an email to:</span><br><span> &nbs= p; [email protected]</span><br><span></span><br><span>= Please visit http://blog.snort.org to stay current on all the latest Snort n= ews!</span><br><span></span><br><span>Please follow these rules: https://sno= rt.org/faq/what-is-the-mailing-list-etiquette</span><br></div></blockquote><= /body></html>= --Apple-Mail-9812D02C-1250-4D5D-9D78-77A699BAFA74-- --===============8766344431510465005== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette --===============8766344431510465005==--