IPS: Update sid-msg.map

Reference: http://oinkmaster.sourceforge.net/faq.shtml

You need to update the sid-msg.map in order for the events to show its description, if sid-msg.map is not updated the events will be like Snort Alert [1:19187:2].

To update the sid-msg.map download the tar file from oinkmaster. Inside the tar file contains a perl script create-sidmap.pl. Use this perl script to update the sid-msg.map by using this command: ./create-sidmap.pl /usr/local/snort/rules > /etc/snort/sid-msg.map

Depends on where is the location of your rules, the path might be different.


One thought on “IPS: Update sid-msg.map

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s