Snort - the de facto standard for intrusion detection/prevention
next up previous contents
Next: Format Up: General Rule Options Previous: Example   Contents


sid

The sid keyword is used to uniquely identify Snort rules. This information allows output plugins to identify rules easily. This option should be used with the rev keyword. (See section [*])

  • $<$100 Reserved for future use
  • 100-1,000,000 Rules included with the Snort distribution
  • $>$1,000,000 Used for local rules

The file sid-msg.map contains a mapping of alert messages to Snort rule IDs. This information is useful when post-processing alert to map an ID to an alert message.



Subsections

Steven Sturges 2007-10-04