Next: Format
Up: Meta-Data Rule Options
Previous: Format
Contents
sid
The sid keyword is used to uniquely identify Snort rules. This information
allows output plugins to identify rules easily. This option should be used
with the rev keyword. (See section )
100 Reserved for future use
- 100-1,000,000 Rules included with the Snort distribution
1,000,000 Used for local rules
The file sid-msg.map contains a mapping of alert messages to Snort rule IDs.
This information is useful when post-processing alert to map an ID to an alert
message.
Subsections
Steven Sturges
2006-12-08
|