Intrusion rule update logs

The Rule Update Log on the Rule Updates page records each intrusion rule update and custom Snort 2 rule import, including its time, user, and status. Each log also identifies the affected rules and components. Deleting a log does not delete the imported objects.

Intrusion rule update log fields

This table explains the fields in intrusion rule update logs.

Intrusion rule update log fields

Field

Description

Action

Identifies how the import affected the object.

Default action

For a rule, the default action defined by the update is Pass, Alert, or Drop. The field is blank for other object types.

Details

Identifies the affected component or rule. For a changed rule, the field displays the GID, SID, and previous revision number in GID:SID:Rev format. The field is blank for a rule that has not changed.

GID

The generator ID for a rule. For example:

  • A GID of 1 identifies a standard text rule.

  • A GID of 3 identifies a shared object rule.

Name

The name of the imported object. For a rule, the name corresponds to the rule’s Message field. For a rule update component, the field displays the component name.

Policy

For an imported rule, the field displays All when the import succeeds and the rule can be enabled in all applicable system-provided default intrusion policies. The field is blank for other object types.

Rev

The revision number for a rule.

Rule update

The rule update file name.

SID

The Snort ID for a rule.

Time

The time and date the import began.

Type

Identifies the imported object as a rule update component, rule, or policy apply. A policy apply record indicates that the option to reapply all policies after the import was enabled.

Action values

The Action field in intrusion rule update logs uses these values.

Action values in intrusion rule update logs

Action

Meaning

new

The rule was stored for the first time.

changed

A rule update component was modified, or a rule was imported with a higher revision number and the same GID and SID.

collision

The import was skipped because the revision conflicts with an existing component or rule.

deleted

The rule was deleted from the rule update.

enabled

A rule, preprocessor, or other feature was enabled in a system-provided default policy.

disabled

A rule was disabled in a system-provided default policy.

drop

A rule was set to Drop and Generate Events in a system-provided default policy.

error

The update or import failed.

apply

The option to reapply all policies after the import was enabled.

Searching intrusion rule update logs

A search from the detailed log view searches the entire database, not only the selected import. Use the time range to limit the results to relevant records.