Snort Rule management

Marc <[email protected]>
Newsgroups gmane.comp.security.ids.snort.sigs
Message-ID <CH2PR19MB41351E43D0267D8CDF4CBAD9A1CF9@CH2PR19MB4135.namprd19.prod.outlook.com>
Hi,

What would be a good reference on managing (not writing) Snort3 Rules?  Specifically, I am running Snort 3.1.6 with SO rules and Pulled Pork.  I am having difficulty removing rules (e.g. a noisy ICMP rule ).  I am looking for a concise reference or alternately a tutorial on commenting out rules and recompiling them.  I have tried commenting out the rule in pulledpork.rules and local.rules and restarting Snort, but that didn't do it.   Thank you.

Regards,
Marc

_______________________________________________
Snort-sigs mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.