[Snort-users] If this, but not this rules

Joel Esler jesler at ...1935...
Tue Nov 24 22:52:31 EST 2009

On Tue, Nov 24, 2009 at 8:28 PM, Jesse Lands <cryptograffiti at ...11827...>wrote:

> Not sure if this even possible, but I want to alert on a specific file
> header flag, but not if it contains another flag.
> Is there a way to write an alert like that?  Not asking for solutions.  If
> there is a spot you can reference I can read it.
You mean to do a positive match, then a negative match?  Yes.

For instance, I want to look for packets with the word "joel" but not the
word "esler"

content:"joel"; content:!"esler";

Joel Esler | 302-223-5974 | gtalk: jesler at ...1935...
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20091124/2712210f/attachment.html>

More information about the Snort-users mailing list