• Support
  • Forums
  • Blogs

Suricata custom rules


New Life Form

After upgrade OSSIM to 5.6.5 suricata custom rules doesn't work.

Configuration of suricata:
alienvault:/etc/suricata# cat suricata.yaml | grep rule-files
include: rule-files.yaml

alienvault:/etc/suricata# cat rule-files.yaml | grep local
- local.rules

Examples of rules that don't work:

pass ip any <>    161 (msg:"SNMP_App"; sid:60;)
pass ip      any  <>  161   (msg:"SNMP_App"; sid:61;)

Does anybody have problems like this?
 Before the update it worked

Share post:

Sign In or Register to comment.