Keyword Filtering
Each rule filter can include one or more keywords in the format:
keyword:argument
where keyword is one of the keywords in the following table and argument is a single, case-insensitive, alphanumeric string to search for in the specific field or fields relevant to the keyword.
Arguments for all keywords except
gid
and
sid
are treated as partial strings. For example, the
argument
123
returns
"12345"
,
"41235"
,
"45123",
and so on. The arguments for
gid
and
sid
return only exact matches; for example,
sid:3080
returns only SID 3080.
Tip | You can search for a partial SID by filtering with one or more character strings. |
The following table describes the specific filtering keywords and arguments you can use to filter rules.
Keyword |
Description |
Example |
---|---|---|
|
Returns one or more rules based on all or part of the Arachnids ID in a rule reference. |
|
|
Returns one or more rules based on all or part of the Bugtraq ID in a rule reference. |
|
|
Returns one or more rules based on all or part of the CVE number in a rule reference. |
|
|
The argument
|
|
|
Returns one or more rules based on all or part of the McAfee ID in a rule reference. |
|
|
Returns one or more rules based on all or part of the rule Message field, also known as the event message. |
|
|
Returns one or more rules based on all or part of the Nessus ID in a rule reference. |
|
|
Returns one or more rules based on all or part of a single alphanumeric string in a rule reference or in the rule Message field. |
|
|
Returns the rule with the exact Snort ID. |
|
|
Returns one or more rules based on all or part of the URL in a rule reference. |
|