Error in registered TalosLightSPD ruleset released on 2026-03-24?

Dheeraj Gupta via Snort-sigs <[email protected]> Wed, 25 Mar 2026 10:57:57 +0530
Newsgroups gmane.comp.security.ids.snort.sigs
Message-ID <CAOsL98NBfu2gmDtX1A+S8QuzCyRi+JXrg4fsns9Kgmp7tieo_A@mail.gmail.com>
--===============1200169303273905921==
Content-Type: multipart/alternative; boundary="00000000000088c8aa064dd28806"

--00000000000088c8aa064dd28806
Content-Type: text/plain; charset="UTF-8"

Hi,

We are using registered ruleset for Snort. After downloading the latest
LightSPD ruleset released on 2026-03-24, our sensor failed to start up with
an error

ERROR: ips.rules:6 can't open ../../rules/3.1.25.0/includes.rules
ERROR: ips.states:6 can't open ../../rules/
3.1.25.0/rulestates-security-ips.states

Looking at the the file lightspd/policies/common/load_ips.lua in the
release, there is a reference to 3.1.25 (which was not there in older
release)

if TALOS.functions.minsnortver_str("3.1.25.0-0") then
   table.insert(ruleDirs, "../../rules/3.1.25.0")
end

while there is no 3.1.25.0 subdirectory in the rules/

Commenting out the above 3 lines allows sensor to start. Is this a problem
with only the registered ruleset?

Thanks,
Dheeraj

--00000000000088c8aa064dd28806
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><div>Hi,</div><div><br></div><div>We are =
using registered
 ruleset for Snort. After downloading the latest LightSPD ruleset=20
released on 2026-03-24, our sensor failed to start up with an error</div><d=
iv><br></div><div>ERROR: ips.rules:6 can&#39;t open ../../rules/<a href=3D"=
http://3.1.25.0/includes.rules" target=3D"_blank">3.1.25.0/includes.rules</=
a><br>ERROR: ips.states:6 can&#39;t open ../../rules/<a href=3D"http://3.1.=
25.0/rulestates-security-ips.states" target=3D"_blank">3.1.25.0/rulestates-=
security-ips.states</a></div><div><br></div><div>Looking at the the file=C2=
=A0lightspd/policies/common/load_ips.lua in the release, there is a referen=
ce to 3.1.25 (which was not there in older release)</div><div><br></div><di=
v>if TALOS.functions.minsnortver_str(&quot;3.1.25.0-0&quot;) then<br>=C2=A0=
 =C2=A0table.insert(ruleDirs, &quot;../../rules/<a href=3D"http://3.1.25.0"=
 target=3D"_blank">3.1.25.0</a>&quot;)<br>end</div><div><br></div><div>whil=
e there is no 3.1.25.0 subdirectory in the rules/</div><div><br></div><div>=
Commenting out the above 3 lines allows sensor to start. Is this a problem =
with only the registered ruleset?</div><div><br></div><div>Thanks,</div><di=
v>Dheeraj</div></div><br></div>

--00000000000088c8aa064dd28806--

--===============1200169303273905921==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-sigs mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!

--===============1200169303273905921==--