[Snort-users] How to enable ALL rules when Pulledpork is ran?

Michael Steele michaels at ...9077...
Mon Feb 8 13:02:35 EST 2016

That was the trick J


Kindest regards,



WINSNORT.com Management Team Member


****************** Established ~ 2001 *******************

*          Visit Us @  <http://www.winsnort.com> http://www.winsnort.com

*      ~~ FREE WinIDS Snort installation guides ~~      *

*               ~~ FREE support forums ~~               *

* Snort: Open Source Network IDS -  <http://www.snort.org>
http://www.snort.org *



From: Y M [mailto:snort at ...15979...] 
Sent: Monday, February 8, 2016 9:52 AM
To: Michael Steele <michaels at ...9077...>
Cc: snort-users at lists.sourceforge.net
Subject: Re: [Snort-users] How to enable ALL rules when Pulledpork is ran?


Add "pcre:." minus the quotes to your enablesid.conf, thanks to shirkdog,
mentioning it some time back.



Sent from Mobile


On Mon, Feb 8, 2016 at 6:41 AM -0800, "Michael Steele"
<michaels at ...9077... <mailto:michaels at ...9077...> > wrote:

I'm trying to figure out how to activate all the rules (for temp testing
purposes) when PP is ran.


I'm using the -nPT as the switches when I run PP on a ruleset that is


All rules are located in the snort.rules file.


Everything is processing normally using the ips_policy=security switch.



-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20160208/f297234e/attachment.html>

More information about the Snort-users mailing list