You need to update the sid-msg.map in order for the events to show its description, if sid-msg.map is not updated the events will be like
Snort Alert [1:19187:2].
To update the sid-msg.map download the tar file from oinkmaster. Inside the tar file contains a perl script create-sidmap.pl. Use this perl script to update the sid-msg.map by using this command:
./create-sidmap.pl /usr/local/snort/rules > /etc/snort/sid-msg.map
Depends on where is the location of your rules, the path might be different.
One thought on “IPS: Update sid-msg.map”
is it possible to update the sid-msg.map with preprocessor rules