[Snort-users] How to enable ALL rules when Pulledpork is ran?

Y M snort at ...15979...
Mon Feb 8 09:51:45 EST 2016

Add "pcre:." minus the quotes to your enablesid.conf, thanks to shirkdog, mentioning it some time back.


Sent from Mobile

On Mon, Feb 8, 2016 at 6:41 AM -0800, "Michael Steele" <michaels at ...9077...<mailto:michaels at ...9077...>> wrote:

I'm trying to figure out how to activate all the rules (for temp testing purposes) when PP is ran.

I'm using the -nPT as the switches when I run PP on a ruleset that is current.

All rules are located in the snort.rules file.

Everything is processing normally using the ips_policy=security switch.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20160208/ac0ee154/attachment.html>

More information about the Snort-users mailing list