Intrusion rule update logs
The Rule Update Log on the Rule Updates page records each intrusion rule update and custom Snort 2 rule import, including its time, user, and status. Each log also identifies the affected rules and components. Deleting a log does not delete the imported objects.
Intrusion rule update log fields
This table explains the fields in intrusion rule update logs.
|
Field |
Description |
|---|---|
|
Action |
Identifies how the import affected the object. |
|
Default action |
For a rule, the default action defined by the update is Pass, Alert, or Drop. The field is blank for other object types. |
|
Details |
Identifies the affected component or rule. For a changed rule,
the field displays the GID, SID, and previous revision number in
|
|
GID |
The generator ID for a rule. For example:
|
|
Name |
The name of the imported object. For a rule, the name corresponds to the rule’s Message field. For a rule update component, the field displays the component name. |
|
Policy |
For an imported rule, the field displays |
|
Rev |
The revision number for a rule. |
|
Rule update |
The rule update file name. |
|
SID |
The Snort ID for a rule. |
|
Time |
The time and date the import began. |
|
Type |
Identifies the imported object as a rule update component, rule, or policy apply. A policy apply record indicates that the option to reapply all policies after the import was enabled. |
Action values
The Action field in intrusion rule update logs uses these values.
|
Action |
Meaning |
|---|---|
|
new |
The rule was stored for the first time. |
|
changed |
A rule update component was modified, or a rule was imported with a higher revision number and the same GID and SID. |
|
collision |
The import was skipped because the revision conflicts with an existing component or rule. |
|
deleted |
The rule was deleted from the rule update. |
|
enabled |
A rule, preprocessor, or other feature was enabled in a system-provided default policy. |
|
disabled |
A rule was disabled in a system-provided default policy. |
|
drop |
A rule was set to Drop and Generate Events in a system-provided default policy. |
|
error |
The update or import failed. |
|
apply |
The option to reapply all policies after the import was enabled. |
Searching intrusion rule update logs
A search from the detailed log view searches the entire database, not only the selected import. Use the time range to limit the results to relevant records.