Snort - the de facto standard for intrusion detection/prevention
next up previous contents
Next: General Rule Quick Reference Up: metadata Previous: metadata   Contents

Format

metadata: key1 value1;
metadata: key1 value1, key2 value2;

Figure: Example Metadata Rule
\begin{figure}\begin{verbatim}alert tcp any any -> any 80 (msg: ''Shared Libra...
...''; metadata:engine shared, soid 3\vert 12345;)\end{verbatim}
\par\end{figure}



Steven Sturges 2007-10-04