Snort mailing list archives

Re: Unknown rule option sip_header


From: waldo kitty <wkitty42 () windstream net>
Date: Wed, 01 Oct 2014 22:07:48 -0400

On 10/1/2014 1:21 PM, Joel Esler (jesler) wrote:
This is a catch 22..  If you load silently, then people think that a rule that
was supposed to be turned on, but failed to load for whatever reason (for
instance the opposite of what you experienced today), then we get hollered at
for NOT failing.  Then when we fail, we get hollered at for failing.

agreed on all parts... how about, if providing a command line "failed rule so 
skip it and execute anyway" log it in similar fashion as other items that 
rightly deserve notification...

-- 
  NOTE: No off-list assistance is given without prior approval.
        Please *keep mailing list traffic on the list* unless
        private contact is specifically requested and granted.

------------------------------------------------------------------------------
Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer
http://pubads.g.doubleclick.net/gampad/clk?id=154622311&iu=/4140/ostg.clktrk
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: