Hi
i used:
./scripts/fingerprintout.py -i ./fingerprints/fingerprints.json
than 16 lines are never matching when running in suricata.
the end before the sid: ends with " content: "||"; rawbytes; distance: 0;"
the content: "||" breaks suricata.
i just removed this part by hand and see now matching rules.
Regards Torsten
Hi i used: ./scripts/fingerprintout.py -i ./fingerprints/fingerprints.json than 16 lines are never matching when running in suricata.
the end before the sid: ends with " content: "||"; rawbytes; distance: 0;" the content: "||" breaks suricata. i just removed this part by hand and see now matching rules. Regards Torsten