pevma / rule2alert

Improvements of/over the original rule2alert
http://code.google.com/p/rule2alert/
56 stars 19 forks source link

flowbit r2a error #1

Closed richrumble closed 9 years ago

richrumble commented 10 years ago

I cat'd a bunch of rules into one file, and when r2a got to the flowbit's it error'd out.

Here is the last few lines: Loaded 11277 rules succesfully! Loading flowbits rules... found only SET in flowbit name ET.HTTP.at.SSL 2013933,set,2013931,set,2013927,set,2013929,set,2013926,set,2013928,set,2013930,set,2013932,set found only SET in flowbit name ms.rdp.established 2014386,set found only SET in flowbit name ET.ass.request 2010757,set found only SET in flowbit name ET.BotccIP 2404101,set,2404103,set,2404105,set,2404107,set,2404109,set,2404111,set,2404113,set,2404115,set,2404117,set,2404119,set,2404121,set,2404123,set,2404125,set,2404127,set,2404129,set,2404131,set,2404133,set,2404135,set,2404137,set,2404139,set,2404141,set,2404143,set,2404145,set,2404147,set found only SET in flowbit name ET.zbot.ua.2106509 2016509,set found only SET in flowbit name ET.bd1 2009240,set

richrumble commented 9 years ago

Let me know when you want me to test the patch, I'm at a stage where I can do a bunch of breaking (aka using) r2a :)

pevma commented 9 years ago

Cool. Apologies for the delay - I will ping you this week at some point. Thank you for the offer!

On Tue, Dec 16, 2014 at 3:34 AM, Rich Rumble notifications@github.com wrote:

Let me know when you want me to test the patch, I'm at a stage where I can do a bunch of breaking (aka using) r2a :)

— Reply to this email directly or view it on GitHub https://github.com/pevma/rule2alert/issues/1#issuecomment-67103754.

Regards, Peter Manev

pevma commented 9 years ago

Fixed through - https://github.com/pevma/rule2alert/commit/8ab350186f65706cca5a5b14e0c76a3431e08f02

Thanks!