<?xml version="1.0"?>
<rss version="2.0"><channel><title>Issues with Rules in the Windows Intrusion Detection system Latest Topics</title><link>https://www.winsnort.com/forum/21-issues-with-rules-in-the-windows-intrusion-detection-system/</link><description>Issues with Rules in the Windows Intrusion Detection system Latest Topics</description><language>en</language><item><title>Pulled Pork Update Error</title><link>https://www.winsnort.com/topic/289-pulled-pork-update-error/</link><description><![CDATA[
<p>
	Hi,
</p>

<p>
	 
</p>

<p>
	I have recently went to upgrade my Snort version and Pulled Pork version. Those seem to have upgraded just fine. What I am having an issue with is trying to update pulled pork after the update. When I run the update command it seems like it can't connect to Talos which is a first time I am seeing that issue. Has anyone seen an issue like this before. In the attached screenshot I am able to browse to the website shown. It almost seems like the Talos side might not allow me in to download said file.
</p>

<p>
	 
</p>

<p>
	Thanks in advance. 
</p>

<p><a href="https://www.winsnort.com/uploads/monthly_2018_03/5ab163db7ab92_PulledPorkError.JPG.ed5956c3d476462b759ae163d3a89804.JPG" class="ipsAttachLink ipsAttachLink_image"><img data-fileid="187" src="https://www.winsnort.com/uploads/monthly_2018_03/5ab163db7ab92_PulledPorkError.JPG.ed5956c3d476462b759ae163d3a89804.JPG" class="ipsImage ipsImage_thumbnailed" alt="Pulled Pork Error.JPG"></a></p>]]></description><guid isPermaLink="false">289</guid><pubDate>Tue, 20 Mar 2018 19:46:39 +0000</pubDate></item><item><title>Pulled Pork update frequency</title><link>https://www.winsnort.com/topic/262-pulled-pork-update-frequency/</link><description><![CDATA[
<p>
	Hi
</p>

<p>
	Firstly, thanks to Morpheus for the quite flawless instructions for installing Snort on Windows and the various additional tutorials.
</p>

<p>
	Just a quick question about Pulled Pork.  I have installed it and everything is working just fine.  I'm just not clear how often the rules and sigs get updated and what the update mechanism is.  Can anyone elaborate?
</p>

<p>
	thanks!
</p>
]]></description><guid isPermaLink="false">262</guid><pubDate>Mon, 27 Feb 2017 21:01:25 +0000</pubDate></item><item><title>General Questions for Pulledpork slave setup</title><link>https://www.winsnort.com/topic/251-general-questions-for-pulledpork-slave-setup/</link><description><![CDATA[
<p>
	Hello,
</p>

<p>
	The my AWS setup continues to progress. I've managed to get success (I think) in running the pulledpork tutorial, however, I do have some lingering questions that concern me where I needed to deviate from the tutorial instructions:
</p>

<p>
	1.) I'm using a Linux mySQL instance for the database. The Apache2 server is also running on the Linux box. Not std for the Winsnort tutorial where it comments on IIS Vs. Apache2 customizations The first instruction in question is to delete all files from a directory structure that is not present on my winIDS snort slave install: C:\IDS\Apache24\htdocs\base\signatures\  The cmd to del all files in the dir does not bother me.
</p>

<p>
	after seeing the file path referenced in the pulledpork.conf file I created the file structure to accommodate the update process. I'm curious if these "signatures" are intended to be added somehow to the MySQL database via apache? The front end I'm using, Snorby, has a listing of signatures that it pulls from the MySQL DB. the front end only reports the original 522 signatures. Any thoughts on how the concepts work for a standard WinIDS deployment? Does Base have an updated sig count of 12000+ signatures after running pulledpork?
</p>

<p>
	2.) When I ran the pulledpork cmd it seemed to go ok - the questions in the forums resolved some concerns - the downloaded signature files totaled 23,499 in the C:\IDS\Apache24\htdocs\base\signatures\ path. when running the pulledpork in ips_policy=security the pp script determines that out of 30577 rules 12275 will be enabled and 18302 will be disabled. I'd like to know more as to why the script decides on which rules to enable / disable 
</p>

<p>
	3.) This is the thing that is of highest concern to me - I know the OS evnironment for the tutorial was a Win 7 machine and I'm installing on the Server counterpart, 2008 R2, but there is a box toward the bottom of the tutorial that claims after restarting the snort server that a Barnyard2 CMD window will just be running minimized in the taskbar area:
</p>

<p>
	" <span style='color: rgb(64, 98, 153); text-transform: none; text-indent: 0px; letter-spacing: normal; font-family: "Helvetica Neue", Helvetica, Arial, sans-serif; font-size: 14px; font-style: normal; font-weight: normal; word-spacing: 0px; float: none; white-space: normal; background-color: rgb(222, 223, 255);'>When the system is rebooted, Barnyard2 will be running in a Minimized window located in the Windows task bar. Opening the Barnyard2 CMD window will display the events as they are being shuttled to the database.</span> "
</p>

<p>
	I don't think I missed any steps, but this is not going to happen in my current install - I'd like to know where I went wrong.
</p>

<p>
	4.) Finally, my last question is concerning automating the Pulledpork updating process. Can WINsnort.com endorse the practice of having a .bat file called by a scheduled task to execute the CMD below on a daily basis? If yes why not include this in the pulledpork tutorial?
</p>

<p>
	Perl d:\winids\pulledpork\pulledpork.pl -c d:\winids\pulledpork\etc\pulledpork.conf -T
</p>

<p>
	Thanks in advance for the feedback.
</p>

<p>
	JVinson
</p>

<p>
	PS - @ Mopheus - did you see my private message? just wanted to confirm you did or not. Thanks.
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">251</guid><pubDate>Fri, 06 Jan 2017 23:02:10 +0000</pubDate></item><item><title>Uname is not recognized as internal or external command</title><link>https://www.winsnort.com/topic/248-uname-is-not-recognized-as-internal-or-external-command/</link><description><![CDATA[
<p>
	trying to update rules with Pulledpork after following tutorial
</p>

<p>
	'uname' is not recognized as an intenal or external command.
</p>

<p>
	The specified Snort binary does not exist.
</p>

<p>
	Please correct the value or specify the FULL rules tarball name in pulledpork.conf!
</p>

<p>
	at d:\winids\pulledpork\pulledpork.pl line 1932
</p>
]]></description><guid isPermaLink="false">248</guid><pubDate>Thu, 29 Dec 2016 18:21:37 +0000</pubDate></item><item><title>Activating all the rules for testing purposes in Pulledpork</title><link>https://www.winsnort.com/topic/205-activating-all-the-rules-for-testing-purposes-in-pulledpork/</link><description><![CDATA[<p>
	You may want to activate all the rules just to make sure everything is working correctly after installing Pulledpork. The policy switch in Pulledpork tells Snort which rules to activate, but in general you may not be seeing any events for some time. This procedure will activate <strong>ALL</strong> the rules. Make <strong>SURE</strong> at the end of the test that you revert back to original policy setting or you may end up with <strong>millions</strong> of events that could bog down the Windows Intrusion Detection System (WinIDS).
</p>

<p>
	 
</p>

<h3>
	<i>To activate all the rules bypassing the original policy setting</i>
</h3>

<p>
	Open a CMD window and type <strong>notepad2 d:\winids\script\etc\enablesid.conf</strong> and tap the <strong>Enter</strong> key.
</p>

<p>
	Scroll down find and change the line below:
</p>

<p>
	<strong>Original Line:</strong> # pcre:.<br>
	<strong>Change to:</strong> pcre:.
</p>

<p>
	Save the file and exit.
</p>

<p>
	At the CMD prompt type <strong>perl d:\winids\script\pulledpork.pl -c d:\winids\script\etc\pulledpork.conf -nPT</strong> and tap the <strong>Enter</strong> key.
</p>

<p>
	<strong>Note: </strong>The added switches (nP) instructs Pulledpork to process the <strong>local</strong> rules bypassing the ips_policy switch setting, and this process should take about two minutes.
</p>

<div class="informationmsg">
	The below is displayed in the terminal window after a successful update.
	<pre>
Rule Stats...
        New:-------0
        Deleted:---0
        Enabled Rules:----27325
        Dropped Rules:----0
        Disabled Rules:---0
        Total Rules:------27325
No IP Blacklist Changes

Done
Please review d:\winids\snort\log\sid_changes.log for additional details
Fly Piggy Fly!
</pre>
</div>

<p>
	<strong>Note:</strong> The verbose output above will display the Rule Stats, showing both enabled rule count, and disabled rule count should be 0.
</p>

<div class="informationmsg errormsg center">
	Do not continue or intervene until '<b>Fly Piggy Fly!</b>' is displayed in the terminal window.
</div>

<p>
	At the CMD prompt type <strong>net stop snort &amp; net start snort</strong> and tap the <strong>Enter</strong> key.
</p>

<p>
	<strong>Note:</strong> Allow a couple of minutes for Barnyard2 to reconnect to the event log file after cycling Snort.
</p>

<p>
	At the CMD prompt type <strong>exit</strong> and tap the <strong>Enter</strong> key.
</p>

<div class="informationmsg warningmsg red">
	<b>Note: Once the test is complete it is imperative to return and complete this tutorial or the end database fill up with millions of useless events.</b>
</div>

<h3>
	<i>To revert back to the original policy setting</i>
</h3>

<p>
	Open a CMD window and type <strong>notepad2 d:\winids\script\etc\enablesid.conf</strong> and tap the <strong>Enter</strong> key.
</p>

<p>
	Scroll down find and change the line below:
</p>

<p>
	<strong>Original Line:</strong> pcre:.<br>
	<strong>Change to:</strong> # pcre:.
</p>

<p>
	Save the file and exit.
</p>

<p>
	At the CMD prompt type <strong>perl d:\winids\script\pulledpork.pl -c d:\winids\script\etc\pulledpork.conf -nPT</strong> and tap the <strong>Enter</strong> key.
</p>

<p>
	<strong>Note: </strong>The added switches (nP) instructs Pulledpork to process the <strong>local</strong> rules using the ips_policy switch setting, and this process should take about two minutes.
</p>

<div class="informationmsg">
	The below is displayed in the terminal window after a successful update.
	<pre>
Rule Stats...
        New:-------0
        Deleted:---0
        Enabled Rules:----9853
        Dropped Rules:----0
        Disabled Rules:---17472
        Total Rules:------27325
No IP Blacklist Changes

Done
Please review d:\winids\snort\log\sid_changes.log for additional details
Fly Piggy Fly!
</pre>
</div>

<p>
	<strong>Note:</strong> The verbose output above will display the Rule Stats, showing both enabled rule count, and disabled rule count.
</p>

<div class="informationmsg errormsg center">
	Do not continue or intervene until '<b>Fly Piggy Fly!</b>' is displayed in the terminal window.
</div>

<p>
	At the CMD prompt type <strong>net stop snort &amp; net start snort</strong> and tap the <strong>Enter</strong> key.
</p>

<p>
	<strong>Note:</strong> Allow a couple of minutes for Barnyard2 to reconnect to the event log file after cycling Snort.
</p>

<p>
	At the CMD prompt type <strong>exit</strong> and tap the <strong>Enter</strong> key.
</p>
]]></description><guid isPermaLink="false">205</guid><pubDate>Mon, 08 Feb 2016 21:42:41 +0000</pubDate></item><item><title>Process rules based on policy change</title><link>https://www.winsnort.com/topic/204-process-rules-based-on-policy-change/</link><description><![CDATA[<p>
	The ips_policy switch has three settings:
</p>

<ol>
	<li>
		balanced
	</li>
	<li>
		connectivity
	</li>
	<li>
		security
	</li>
</ol>

<p>
	The default ips_policy switch is set to security. If at any time you want to change the ips_policy switch in the pulledpork.conf it will require an additional two switches added to the end of the Pulledpork run line to process the new ips_policy.
</p>

<p>
	Open a <span style="color:#525252">CMD prompt type as Administrator and type '</span><strong>perl d:\winids\pulledpork\pulledpork.pl -c d:\winids\pulledpork\etc\pulledpork.conf -<span style="color: rgb(255, 0, 0);">nP</span>T'</strong> (less the outside quotes) and tap the Enter key.
</p>

<p>
	The above run line will only process the local rules for the new policy change on the fly! This run line will not update the rules from the rules repository. It will only update the policy selection from the existing set of rules!
</p>

<p>
	The rules should be checked for errors after the update for validation, and Snort must be cycled!
</p>

<p>
	Open a <span style="color:#525252">CMD prompt type as Administratort '<strong>d:\winids\snort\bin\snort -c d:\winids\snort\etc\snort.conf -l d:\winids\snort\log -i</strong></span><strong><span style="color:#ff0000">x</span></strong><span style="color:#525252"><strong><span> </span>-T</strong>' (less the outside quotes) and tap the 'Enter' key.</span><br style="color:#525252">
	 
</p>

<p>
	<b style="color: rgb(64, 98, 153);">Note:</b><span style="color: rgb(64, 98, 153);"> </span><span style="color: rgb(64, 98, 153);">In the interface switch above (-i</span><span style="color: rgb(255, 0, 0);">x</span><span style="color: rgb(64, 98, 153);">), the</span><span style="color: rgb(64, 98, 153);"> </span><span style="color: rgb(255, 0, 0);">x</span><span style="color: rgb(64, 98, 153);"> </span><span style="color: rgb(64, 98, 153);">will be substituted for the</span><span style="color: rgb(64, 98, 153);"> </span><b style="color: rgb(64, 98, 153);">Index</b><span style="color: rgb(64, 98, 153);"> </span><span style="color: rgb(64, 98, 153);">number of the monitoring NIC.</span>
</p>

<div style="color:#406299">
	If all the tests are passed, the following is a confirmation that the Snort configuration file and rules have tested good.
	<pre>
Snort successfully validated the configuration!
Snort exiting</pre>
</div>
]]></description><guid isPermaLink="false">204</guid><pubDate>Mon, 08 Feb 2016 04:20:41 +0000</pubDate></item><item><title>No such file or directory - blacklist?</title><link>https://www.winsnort.com/topic/188-no-such-file-or-directory-blacklist/</link><description><![CDATA[
<p>Any idea what is going on here?</p>

<pre class="ipsCode prettyprint">
'uname' is not recognized as an internal or external command,
operable program or batch file.
Checking latest MD5 for snortrules-snapshot-2975.tar.gz....
Rules tarball download of snortrules-snapshot-2975.tar.gz....
        They Match
        Done!
IP Blacklist download of http://talosintel.com/files/additional_resources/ips_bl
acklist/ip-filter.blf....
Reading IP List...
Couldn't read d:\winids\pulledpork\temp/888.85498046875-black_list.rules - No su
ch file or directory
 at d:\winids\pulledpork\pulledpork.pl line 540
        main::read_iplist('HASH(0x38eba80)', 'd:\winids\pulledpork\temp/888.8549
8046875-black_list.rules') called at d:\winids\pulledpork\pulledpork.pl line 431

        main::rulefetch('open', 'IPBLACKLIST0', 'd:\winids\pulledpork\temp/', 'h
ttp://talosintel.com/files/additional_resources/ips_blacklis...') called at d:\w
inids\pulledpork\pulledpork.pl line 1946
</pre>

<p> </p>
]]></description><guid isPermaLink="false">188</guid><pubDate>Thu, 01 Oct 2015 14:33:49 +0000</pubDate></item><item><title>New to PulledPork- Dealing with SO_RULE</title><link>https://www.winsnort.com/topic/168-new-to-pulledpork-dealing-with-so_rule/</link><description><![CDATA[
<p>I have completed installing and configuring for PulledPork.  Now I see all of these SO_RULES in the snort.conf file.  They are all commented out.  I am not catching any events.</p>

<p>I see no other rules in snort.conf other than SO_RULEs.  Are there supposed to be regular rules there?  If yes, how do I get them there?</p>

<p>I have started to read-</p>

<p>SO_Rules are not compatible with Windows.<iframe data-embedcontent="" frameborder="0" src="https://www.winsnort.com/topic/67-what-are-shared-object-rules-sos-and-why-not-windows-compatable?do=embed"></iframe></p>
]]></description><guid isPermaLink="false">168</guid><pubDate>Thu, 04 Jun 2015 20:13:30 +0000</pubDate></item><item><title>Error while testing update of rules and signatures using Pulledpork</title><link>https://www.winsnort.com/topic/167-error-while-testing-update-of-rules-and-signatures-using-pulledpork/</link><description><![CDATA[
<p>I was tryling testing update of rules and signatures using Pulledpork, but I had the following error message:</p>

<p>d:\winids\pulledpork\pulledpork.pl -c d:\winids\pulledpork\e<br>
tc\pulledpork.conf -T</p>

<p>    <a href="http://code.google.com/p/pulledpork/" rel="external nofollow">http://code.google.com/p/pulledpork/</a><br>
      _____ ____<br>
     `----,\    )<br>
      `--==\\  /    PulledPork v0.7.0 - Swine Flu!<br>
       `--==\\/<br>
     .-~~~~-.Y|\\_  Copyright (C) 2009-2013 JJ Cummings<br>
  @_/        /  66\_  <a href="mailto:cummingsj@gmail.com" rel="external nofollow">cummingsj@gmail.com</a><br>
    |    \   \   _(")<br>
     \   /-| ||'--'  Rules give me wings!<br>
      \_\  \_\\<br>
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~</p>

<p>'uname' is not recognized as an internal or external command,<br>
operable program or batch file.<br>
Checking latest MD5 for snortrules-snapshot-xxxx.tar.gz....<br>
        Error 422 when fetching <a href="https://www.snort.org/reg-rules/snortrules-snaps" rel="external nofollow">https://www.snort.org/reg-rules/snortrules-snaps</a><br>
hot-xxxx.tar.gz.md5 at D:\winids\pulledpork\pulledpork.pl line 463<br>
        main::md5file('20d5e532f75a4aaceee29638b0458901dd617c16', 'snortrules-sn<br>
apshot-xxxx.tar.gz', 'd:\winids\pulledpork\temp/', '<a href="https://www.snort.org/reg-ru" rel="external nofollow">https://www.snort.org/reg-ru</a><br>
les/') called at D:\winids\pulledpork\pulledpork.pl line 1847</p>

<p>Could you help me to fix this please. Regards Jan</p>

<p> </p>
]]></description><guid isPermaLink="false">167</guid><pubDate>Tue, 02 Jun 2015 10:19:12 +0000</pubDate></item><item><title>Error on Test of Rules and Signatures Update Test</title><link>https://www.winsnort.com/topic/165-error-on-test-of-rules-and-signatures-update-test/</link><description><![CDATA[
<p>The configuration of Pulled Pork installation is verified.  Now testing update of rules and signatures using Pulledpork.</p>

<p>The attachment shows the error that results from the test.  I have gone to the referenced line numbers shown in the error message but have not been able to determine a resolution.</p>

<p>Please advise.</p>

<p><a href="https://www.winsnort.com/uploads/monthly_2015_06/Rules_Signature_Test_Error.JPG.1dcdf1dd6fdf7c4ae4a26f5ed2999599.JPG" class="ipsAttachLink ipsAttachLink_image"><img data-fileid="70" src="https://www.winsnort.com/uploads/monthly_2015_06/Rules_Signature_Test_Error.thumb.JPG.cb4a4e78a4b9f64748c5fc61c86cd8b6.JPG" class="ipsImage ipsImage_thumbnailed" alt="Rules_Signature_Test_Error.JPG"></a></p>]]></description><guid isPermaLink="false">165</guid><pubDate>Mon, 01 Jun 2015 15:43:09 +0000</pubDate></item><item><title>Waiting for New Data after configuring PulledPork</title><link>https://www.winsnort.com/topic/155-waiting-for-new-data-after-configuring-pulledpork/</link><description><![CDATA[
<p>Hi All</p>

<p>So my Barnyard2 cmd is just sitting at a waiting for new data prompt and has been like this all weekend, there is no data being passed to winids console either. Seems to me that barnyard is not receiving any traffic.  </p>

<p>If i run the test commands : d:\winids\snort\bin\snort -v -i1 or i2 both display's traffic and (<span style="line-height:22.3999996185303px;">warning: </span>no preprocessors configured for policy 0).</p>

<p>If i run <span style="color:rgb(82,82,82);line-height:22.3999996185303px;">d:\winids\activators\by2-test config file successfully loads. </span></p>

<p><span style="color:rgb(82,82,82);line-height:22.3999996185303px;">Running 'perl d:\winids\pulledpork\pulledpork.pl -c d:\winids\pulledpork\etc\pulledpork.conf -T completes in about 30 mins no erros</span></p>

<p><span style="color:rgb(82,82,82);line-height:22.3999996185303px;">Running d:\winids\snort\bin\snort </span><span style="color:rgb(255,0,0);line-height:22.3999996185303px;"><b>-c d:\winids\snort\etc\snort.conf -l d:\winids\snort\log -i1</b></span><span style="color:rgb(82,82,82);line-height:22.3999996185303px;"> -T (snort validated the config file successfully)</span></p>

<p><span style="color:rgb(82,82,82);line-height:22.3999996185303px;">All services are running and started</span></p>

<p>Does anyone have any ideas what i am missing ?</p>

<p>Thanks</p>

<p>Gary</p>

<p> </p>

<p> </p>
]]></description><guid isPermaLink="false">155</guid><pubDate>Mon, 18 May 2015 11:11:59 +0000</pubDate></item><item><title>'uname' error</title><link>https://www.winsnort.com/topic/151-uname-error/</link><description><![CDATA[
<p>I am in the process of setting up to pull the rules automatically via pulledpork, however when I run this command "perl d:\winids\pulledpork\pulledpork.pl -c d:\winids\pulledpork\etc\pulledpork.conf -T" (without the commas of course) I get 'uname' is not recognised as an internal or external command, operable command or batch file.  It is also throwing up errors in lines 463 and 1847.  Has anyone encountered this and has any idea of a solution?<br><br>
Thanks<br>
Belnando</p>
]]></description><guid isPermaLink="false">151</guid><pubDate>Sat, 09 May 2015 14:20:34 +0000</pubDate></item><item><title>IGMP protocol not supported</title><link>https://www.winsnort.com/topic/138-igmp-protocol-not-supported/</link><description><![CDATA[<p>Good guide, however less clearly explained than the Snort setup guide. After completing the guide, all rules are DISABLED, you have to add the complete list of classifications in the enablesid.conf, before rules become enabled. But that helps in learning how it works, so thanks!</p>

<p>However, the real issue I'm having is that the igmp protocol doesn't seem to be supported. Upon testing Snort, I receive an error:</p>

<pre style="color:rgb(0,0,0);line-height:normal;margin:0em;">
Invalid protocol name for
"ip_proto" rule option: "igmp".</pre>

<p><span style="line-height:22.3999996185303px;">Therefore, I have disabled these rules in my disable.conf (</span><span style="font-family:Arial, Helvetica, FreeSans, sans-serif;font-size:13.3333330154419px;line-height:17.3333339691162px;">pcre:ip_proto:igmp). Any idea how to enable support for the igmp protocol? (21 rules are disabled by this regular expression, so it is not such a big deal, but still).</span></p>

<p> </p>

<p><span style="font-family:Arial, Helvetica, FreeSans, sans-serif;font-size:13.3333330154419px;line-height:17.3333339691162px;">UPDATE: Hmm it's pretty strange, cause Snort doesn't throw an error on 'ip_proto:2', even though that is exactly the same as syaing 'ip_proto:igmp'. Maybe a very small issue in the protocol number to name link? Can that link be changed manually?</span></p>
]]></description><guid isPermaLink="false">138</guid><pubDate>Sun, 26 Apr 2015 09:15:37 +0000</pubDate></item><item><title>snort.exe fails to start</title><link>https://www.winsnort.com/topic/125-snortexe-fails-to-start/</link><description><![CDATA[
<p>Hi Morpheus,</p>
<p>I've installed PulledPork per the instructions, went back and deleted everything, restored to a known good backup taken from right before I started the install, and did everything over. No matter what I try I can't get snort.exe to start again? Would it be helpful if I copied my pulledport.conf and snort.conf files here? Any help would be greatly appreciated. <img src="https://www.winsnort.com/uploads/emoticons/default_smile.png" alt=":)"></p>
<p> </p>
<p>Thanks,</p>
<p>KiRyah</p>
]]></description><guid isPermaLink="false">125</guid><pubDate>Tue, 03 Mar 2015 22:47:18 +0000</pubDate></item><item><title>Local rules name in Base</title><link>https://www.winsnort.com/topic/116-local-rules-name-in-base/</link><description><![CDATA[<p>Hi!</p>
<p> </p>
<p>I've problem with local rules. In BASE local rule not shows name (there is only gid:sid:rev i suppose). After updating pulled pork i ran create sid-map and there is created name for local rule. Barnyard shows rules with names too. What should be update to see names of rule in BASE?</p>
<p>And i've one off topic question - how to make autorisation to BASE page?</p>
<p> </p>
<p>thanks</p>
<p>kjannasz</p>
]]></description><guid isPermaLink="false">116</guid><pubDate>Thu, 18 Dec 2014 13:48:04 +0000</pubDate></item><item><title>Compilation error Line 29</title><link>https://www.winsnort.com/topic/103-compilation-error-line-29/</link><description><![CDATA[<p>When running this command: perl d:winidspulledporkpulledpork.pl -c d:winidspulledporketcpulledpork.conf -T it fails with--compilation aborted at D:winidspulledprotpulledpork.pl line 29.</p>
<p>When looking at line 29 for pulledpork.pl there is line called 'use sys::syslog;'</p>
<p>Has anyone else had or seen this problem ?</p>
]]></description><guid isPermaLink="false">103</guid><pubDate>Mon, 27 Oct 2014 19:07:08 +0000</pubDate></item><item><title>Events are not being triggered after adding this add-on</title><link>https://www.winsnort.com/topic/65-events-are-not-being-triggered-after-adding-this-add-on/</link><description><![CDATA[<p><span style="font-family:arial, helvetica, sans-serif;">Morpheus,</span></p>
<p> </p>
<p><span style="font-family:arial, helvetica, sans-serif;">After adding the PulledPork add-on events have stopped. I went back thru my snort conf file following the update tutorial and the only discrepancies I found had to do with the preproc_rule paths.  In the update tutorial, the rules are turned on, in the PulledPork tutorial, they are turned off.  Once I turned them back on, events started spooling to the unified2 file consistently.  Which is the correct configuration?  </span></p>
]]></description><guid isPermaLink="false">65</guid><pubDate>Mon, 18 Aug 2014 13:46:45 +0000</pubDate></item><item><title>Missing White_List.rules</title><link>https://www.winsnort.com/topic/51-missing-white_listrules/</link><description><![CDATA[<p>
	So I got through the setup of pulled pork with no real problems. I finally get to the last step of running the Snort self-test using the command line
</p>

<p>
	<span style="color: rgb(40, 40, 40); font-family: Helvetica, arial, sans-serif;">d:winidssnortbinsnort </span><span style="color: rgb(255, 0, 0); font-family: Helvetica, arial, sans-serif;"><b>-c d:\winids\snort\etc\snort.conf -l d:\winids\snort\log -i1</b></span><span style="color: rgb(40, 40, 40); font-family: Helvetica, arial, sans-serif;"> -T</span>
</p>

<p>
	<span style="color: rgb(40, 40, 40); font-family: Helvetica, arial, sans-serif;">It comes back with an error </span>
</p>

<p>
	<span style="font-size: 14px;">ERROR: d:\winids\snort\etc\snort.conf(507) =&gt; Unable to open address file d:\win</span><span style="font-size: 14px;">ids\snort\rules\white_list.rules, Error: No such file or directory </span><span style="font-size: 14px;">Fatal Error, Quitting..</span>
</p>

<p>
	Not sure what I messed up exactly.
</p>
]]></description><guid isPermaLink="false">51</guid><pubDate>Wed, 30 Jul 2014 17:48:58 +0000</pubDate></item><item><title>Waiting for New Data after configuring PulledPork Setup</title><link>https://www.winsnort.com/topic/34-waiting-for-new-data-after-configuring-pulledpork-setup/</link><description><![CDATA[<p>Hi,</p>
<p>   Please help!! After following the pulledpork configuration steps, I have not been able to get any data into the database. In my Barnyard window it just says "Waiting for New Data". I have gone through several suggestions as to why this is the case but no resolution. I have added in the test.rules to the snort.conf files and have seen data coming in. I have also installed wireshark on the box and have verified that the monitor port is seeing the data. My network administrator have verified that the mirrored port is setup correctly. I just cannot get it to be written to the database. Any help is greatly appreciated. Thank you.</p>
]]></description><guid isPermaLink="false">34</guid><pubDate>Thu, 12 Jun 2014 19:58:49 +0000</pubDate></item></channel></rss>
