Skip to content

registered ruleset does not have *.states files for builtin rules #14

Description

@NDietrich

The registered rulesets does not have *.states files included in the 'builtins' folder to enable/disable the rules based on ips_policy
The LightSPD ruleset does have *.states files in this folder. The error received is:

WARNING: Error getting policy information from /tmp/Pulledpork-2021.07.08-13.57.32/extracted_rulesets/snortrules-snapshot-3150//builtins/rulestates-balanced-ips.states

Talos needs to decide if they are going to include the builtin *.states files in the registered ruleset (in which case we don't have to do anything), or we'll have to enable all rules manually, unless the ips_policy is 'none', in which case we'll disable all rules.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions