Bug #172

Multiple issues when using a threshold.config file

Added by Will Metcalf almost 4 years ago. Updated over 3 years ago.

Status:ClosedStart date:06/04/2010
Priority:NormalDue date:06/11/2010
Assignee:Pablo Rincon% Done:

100%

Category:-Estimated time:2.50 hours
Target version:0.9.2

Description

1.We should be defaulting s->gid to 1 sometime during rule parsing. Currently we only set this properly for alerts inside of src/detect-engine-alert.c. Failing to default this to 1 causes proper use of the threshold.config file to fail as currently all gid's default to 0.

2.We should include an example of how to specify the use of a threshold.config file in suricata.yaml i.e.
threshold-file: /etc/suricata/threshold.config

3.All of the examples from the snort manual and from the doc/README.filters show multi-line examples using "\" we don't seem to properly parse multi-line entries in this file.
[17475] 4/6/2010 -- 12:54:43 - (util-threshold-config.c:177) <Error> (SCThresholdConfAddThresholdtype) -- [ERRCODE: SC_ERR_PCRE_MATCH(2)] - pcre_exec parse error, ret 1, string event_filter \
[17475] 4/6/2010 -
12:54:43 - (util-threshold-config.c:177) <Error> (SCThresholdConfAddThresholdtype) -- [ERRCODE: SC_ERR_PCRE_MATCH(2)] - pcre_exec parse error, ret 1, string gen_id 1, \
[17475] 4/6/2010 -
12:54:43 - (util-threshold-config.c:177) <Error> (SCThresholdConfAddThresholdtype) -- [ERRCODE: SC_ERR_PCRE_MATCH(2)] - pcre_exec parse error, ret 1, string sig_id 2003292, \
[17475] 4/6/2010 -
12:54:43 - (util-threshold-config.c:177) <Error> (SCThresholdConfAddThresholdtype) -- [ERRCODE: SC_ERR_PCRE_MATCH(2)] - pcre_exec parse error, ret 1, string type both, \
[17475] 4/6/2010 -
12:54:43 - (util-threshold-config.c:177) <Error> (SCThresholdConfAddThresholdtype) -- [ERRCODE: SC_ERR_PCRE_MATCH(2)] - pcre_exec parse error, ret -1, string track by_src, \

[17475] 4/6/2010 -- 12:54:43 - (util-threshold-config.c:177) <Error> (SCThresholdConfAddThresholdtype) -- [ERRCODE: SC_ERR_PCRE_MATCH(2)] - pcre_exec parse error, ret -1, string count 1, \

[17475] 4/6/2010 -- 12:54:43 - (util-threshold-config.c:177) <Error> (SCThresholdConfAddThresholdtype) -- [ERRCODE: SC_ERR_PCRE_MATCH(2)] - pcre_exec parse error, ret -1, string seconds 60

History

#1 Updated by Victor Julien almost 4 years ago

  • Status changed from New to Closed
  • Assignee changed from OISF Dev to Pablo Rincon
  • % Done changed from 0 to 100

Fixed in the current master.

#2 Updated by Victor Julien over 3 years ago

Item 1 was actually not fixed yet. Patch applied to the current master.

Also available in: Atom PDF