[Snort-users] Content-list rule option

Jose Ortiz cissp2k8 at ...11827...
Tue Aug 7 11:57:18 EDT 2012


I have this rule on 2.9.3 :
alert tcp any any -> any any
(content-list:"porn";msg:"test";rev:1;sid:99990000001001;)

I get the following error:

ERROR: /etc/snort/rules/local.rules(6) Unknown rule option: 'content-list'.
Fatal Error, Quitting..

What is the alternative to "content-list"?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20120807/4882660e/attachment.html>


More information about the Snort-users mailing list