Add Custom Rules to Rule Groups
Uploading custom rules in the management center adds the custom rules that you have created locally to the list of all the Snort 3 rules.
Procedure
Step 1 | Choose . | ||
Step 2 | Click Snort 3 All Rules tab. | ||
Step 3 | Click the Tasks drop-down list. | ||
Step 4 | Click Upload Snort 3 Rules. | ||
Step 5 | Drag and drop the .txt or .rules file that contains the Snort 3 custom rules that you have created. | ||
Step 6 | Click OK.
| ||
Step 7 | Associate rules to a rule group to add the new rules to that group. You can also create a new custom rule group (by clicking the Create New Custom Rule Group link) and then add the rules to the new group.
| ||
Step 8 | Choose either of the following:
| ||
Step 9 | Click Next. Review the summary to know the new rule IDs that are being added and optionally download it. | ||
Step 10 | Click Finish. |
Important | The rule action of all the uploaded rules is in the disabled state. You have to change them to the required state to ensure the rules are active. |
What to do next
-
Uploading custom rules in the management center adds the custom rules that you have created to the list of all the Snort 3 rules. To enforce these custom rules on the traffic, add and enable these rules in the required intrusion policies. For information on adding rule groups with custom rules to an intrusion policy, see Add Rule Groups with Custom Rules to an Intrusion Policy. For information on enabling custom rules, see Manage Custom Rules in Snort 3.
-
Deploy configuration changes; see Deploy Configuration Changes.