AlienVault-OTX / OTX-Suricata

The OTX Suricata Rule Generator can be used to create the rules and configuration for Suricata to alert on indicators from your OTX account.
https://otx.alienvault.com
106 stars 32 forks source link

rules configuration error #15

Open vncloudsco opened 3 years ago

vncloudsco commented 3 years ago

rules configuration error after getting the rules we can't use them get error like below,

Suricata Version 6.0.3

22/8/2021 -- 06:17:19 - <Error> - [ERRCODE: SC_ERR_DUPLICATE_SIG(176)] - Duplicate signature "alert http any any -> $HOME_NET any (msg:"OTX - FILE MD5 from pulse b'BRONZE UNION Cyberespionage Persists Despite Disclosures'";  filemd5:md5file/595f8a578737585d5df566c5.txt; reference: url, otx.alienvault.com/pulse/595f8a578737585d5df566c5; sid:414779; rev:1;)"
22/8/2021 -- 06:17:19 - <Error> - [ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - error parsing signature "alert http any any -> $HOME_NET any (msg:"OTX - FILE MD5 from pulse b'BRONZE UNION Cyberespionage Persists Despite Disclosures'";  filemd5:md5file/595f8a578737585d5df566c5.txt; reference: url, otx.alienvault.com/pulse/595f8a578737585d5df566c5; sid:414779; rev:1;)" from file /var/lib/suricata/rules/otx_file_rules.rules at line 1753
22/8/2021 -- 06:17:19 - <Error> - [ERRCODE: SC_ERR_DUPLICATE_SIG(176)] - Duplicate signature "alert http any any -> $HOME_NET any (msg:"OTX - FILE MD5 from pulse b'XData ransomware attacked users in Ukraine'";  filemd5:md5file/595613f3e7adef22e04aac28.txt; reference: url, otx.alienvault.com/pulse/595613f3e7adef22e04aac28; sid:418597; rev:1;)"