This was my assumption before. We used to just use 'pulledpork.pl -c /etc/snort/pulledpork-users.conf' and it would always change the rules, even if there was no new rule files to download. So, that being said, I need to make sure that what I thought was happening is really happening.
So I should be running the below line in my scheduled cron file to check for new rule updates, and I should be executing the same run line to process any new rule modifications, or configuration updates?
Also, does PP know if the ‘ips_policy=’ in the pulledpork.conf gets changed when the below line is ran each time?
perl –n –P d:\winids\pulledpork\pulledpork.pl –c d:\winids\pulledpork\etc\pulledpork.conf -T
Best regards,
Michael...
I can see this so just to confirm. I’m not running PP but I think I might need to adjust my Windows guided install for installing the rules on a new install, and for updating after that.
The guided install has the installer running the below line to install the rules on a new install, and is used in the cron for continuing to check and install new a rule set releases.
perl d:\winids\pulledpork\pulledpork.pl –c d:\winids\pulledpork\etc\pulledpork.conf -T
The above is where I have left the guided install.
I guess I need to add instructions for the installer to manually update PP after changes made to PP.
perl d:\winids\pulledpork\pulledpork.pl –c d:\winids\pulledpork\etc\pulledpork.conf -P -T
If I understand; using the -n would be used when changing the ‘ips_policy=’ setting?
perl d:\winids\pulledpork\pulledpork.pl –c d:\winids\pulledpork\etc\pulledpork.conf –n -P -T
I can see this so just to confirm. I’m not running PP but I think I might need to adjust my Windows guided install for installing the rules on a new install, and for updating after that.
The guided install has the installer running the below line to install the rules on a new install, and is used in the cron for continuing to check and install new a rule set releases.
perl d:\winids\pulledpork\pulledpork.pl –c d:\winids\pulledpork\etc\pulledpork.conf -T
The above is where I have left the guided install.
I guess I need to add instructions for the installer to manually update PP after changes made to PP.
perl d:\winids\pulledpork\pulledpork.pl –c d:\winids\pulledpork\etc\pulledpork.conf -P -T
If I understand; using the -n would be used when changing the ‘ips_policy=’ setting?