Snort mailing list archives

Order on snort rules


From: "Nadia Guerroumi" <n_guerro () ece concordia ca>
Date: Wed, 28 Jan 2004 14:26:42 -0500

PLease is there any order on the execution of snort rules.
If for example I put in a file test.rules those two rules:
alert udp any any -> 10.0.1.255 any (msg:"BZ1";)

alert udp any any -> any any (msg:"BZ2";)



And if I have such alert for 10.0.1.255, wich rule snort will use??

Is there any order?? Because I don"t have the two messages simulanously  BZ1 and Bz2!!

Could you give me any links about HOW THE RULES AND IN WICH ORDER ARE THEY EXECUTED???

Thank you very much!!



Current thread: