if it's commented out in /usr/local/etc/snort/rules/snort.rules then
it's disabled... sid-msg.map has nothing to do with rule state.. to
see what is enabled grep through the rules.. grep
'/^(alert|drop|pass)/' /usr/local/etc/snort/rules/snort.rules
There is no simple way to see what all rules are in what state.. the
newer version of PP in svn breaks the rules out by category in the
/usr/local/etc/snort/rules/snort.rules file so that helps but...
JJC
> --
> You received this message because you are subscribed to the Google Groups
> "pulledpork users" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to
pulledpork-use...@googlegroups.com.
> To post to this group, send email to
pulledpo...@googlegroups.com.
> Visit this group at
http://groups.google.com/group/pulledpork-users?hl=en.
> For more options, visit
https://groups.google.com/groups/opt_out.
>
>