Snort - the de facto standard for intrusion detection/prevention
next up previous contents
Next: Format Up: General Rule Options Previous: Format   Contents

metadata

The metadata tag allows a rule writer to embed additional information about the rule, typically in a key-value format. Certain metadata keys and values have meaning to Snort and are listed in Table [*]. Keys other than those listed in the table are effectively ignored by Snort and can be free-form, with a key and a value. Multiple keys are separated by a comma, while keys and values are separated by a space.

Table: Snort Metadata Keys
Key Description Value Format
engine Indicate a Shared Library Rule "shared"
soid Shared Library Rule Generator and SID gid$\vert$sid

The examples in Figure [*] show an stub rule from a shared library rule. The first uses multiple metadata keywords, the second a single metadata keyword, with keys separated by commas.



Subsections

Steven Sturges 2007-10-04