Snort mailing list archives

Rule update question


From: "Nick Duda" <nduda () VistaPrint com>
Date: Mon, 14 Jun 2004 14:42:36 -0400

Silly question, I just drew a blank as I once did this.... 

How can I set oinkmaster when coming to a rule that was modified
manually to skip it, but I don't want it disabled. Say I modified the
rule from :

Example:
Alert icmp $EXTERNAL_NET any -> $HOME_NET 
To
Alert icmp $EXTERNAL_NET any -> ![x.x.x.x} 

I don't recall me having to disable the SID and doing one manual in a
custom rule file (i.e. local.rules)

Thanks,
Nick




Current thread: