Title: How to find specific snort rule? > Solved Post by: seh2000 on Wednesday 01 February 2012, 07:03:04 am Hi all,
I have been away from the forum on few for a long period due to . Upgraded to the EFW 2.5.1 thanks to the team for a great job. Now, I need to deactivate a few of the SNORT rules, but how do I find the actual rule in the rule files? Lets say I want to deactivate this rule "[1:2002157:9] ET POLICY Skype User-Agent detected..." the in which of the files do I find this rule? Like it is not in the files 'auto/emerging-virus.rules' or in 'auto/emerging-policy.rules' I know 2002157 is the SNORT ID and I know I find the rule in one of the rule files, but which one? Is there somewhere a list showing each rule in each file? Your input is much appreciated. BR// Steen Oops!!! Solved, in the example did not check the 'auto/emerging-policy.rules' file properly! Sorry about! Steen |