[Snort-users] How to enable ALL rules when Pulledpork is ran?

Michael Steele michaels at ...9077...
Mon Feb 8 13:02:35 EST 2016


That was the trick J

 

Kindest regards,

Michael...

 

WINSNORT.com Management Team Member

--

****************** Established ~ 2001 *******************

*          Visit Us @  <http://www.winsnort.com> http://www.winsnort.com
*

*      ~~ FREE WinIDS Snort installation guides ~~      *

*               ~~ FREE support forums ~~               *

* Snort: Open Source Network IDS -  <http://www.snort.org>
http://www.snort.org *

*********************************************************

 

From: Y M [mailto:snort at ...15979...] 
Sent: Monday, February 8, 2016 9:52 AM
To: Michael Steele <michaels at ...9077...>
Cc: snort-users at lists.sourceforge.net
Subject: Re: [Snort-users] How to enable ALL rules when Pulledpork is ran?

 

Add "pcre:." minus the quotes to your enablesid.conf, thanks to shirkdog,
mentioning it some time back.

 

YM

Sent from Mobile

 





On Mon, Feb 8, 2016 at 6:41 AM -0800, "Michael Steele"
<michaels at ...9077... <mailto:michaels at ...9077...> > wrote:

I'm trying to figure out how to activate all the rules (for temp testing
purposes) when PP is ran.

 

I'm using the -nPT as the switches when I run PP on a ruleset that is
current.

 

All rules are located in the snort.rules file.

 

Everything is processing normally using the ips_policy=security switch.

 

Thanks.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20160208/f297234e/attachment.html>


More information about the Snort-users mailing list