Snort and ET ruleset sid-msg.map don't merge during rule update
-
I'm running the lastest snort 2.9.2.3 pkg v. 2.5.1 on pfsense 2.1 beta. For the life of me, I can't remember if the sid-msg.map file merge before all the recent changes made to snort or not.
The issue is which ever ruleset is downloaded/copied last wins the sid-msg.map file. Normally snort/pfSense wouldn't care.. But if your using barnyard2, this makes big difference. Bardyard2 uses this file to send add info about the alert that was triggered.. So lets say if a Snort ruleset was the last to be downloaded but a ET rule is trigger. Only the SID is sent out. If it was a snort rule that was triggered: the SID, alert name, alert reference url will all be sent out. It goes back and forth base on where ruleset was updated last.
If what i wrote doesnt make sense, use the below links to see the difference:
ET Rules updated last:
https://dl.dropbox.com/u/11597356/pfSense/ET-sid-msg.mapSnort Rules updated last:
https://dl.dropbox.com/u/11597356/pfSense/snort-sid-msg.map