IPS: Update sid-msg.map

Reference: http://oinkmaster.sourceforge.net/faq.shtml

You need to update the sid-msg.map in order for the events to show its description, if sid-msg.map is not updated the events will be like Snort Alert [1:19187:2].

To update the sid-msg.map download the tar file from oinkmaster. Inside the tar file contains a perl script create-sidmap.pl. Use this perl script to update the sid-msg.map by using this command: ./create-sidmap.pl /usr/local/snort/rules > /etc/snort/sid-msg.map

Depends on where is the location of your rules, the path might be different.

About these ads
This entry was posted in IDS/IPS, Security and tagged . Bookmark the permalink.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s