Snort mailing list archives
Rule update question
From: "Nick Duda" <nduda () VistaPrint com>
Date: Mon, 14 Jun 2004 14:42:36 -0400
Silly question, I just drew a blank as I once did this.... How can I set oinkmaster when coming to a rule that was modified manually to skip it, but I don't want it disabled. Say I modified the rule from : Example: Alert icmp $EXTERNAL_NET any -> $HOME_NET To Alert icmp $EXTERNAL_NET any -> ![x.x.x.x} I don't recall me having to disable the SID and doing one manual in a custom rule file (i.e. local.rules) Thanks, Nick
Current thread:
- Rule update question Nick Duda (Jun 14)
- Re: Rule update question Andreas Östling (Jun 15)
- Re: Rule update question Andreas Östling (Jun 23)
- Re: Rule update question Andreas Östling (Jun 15)