Project

General

Profile

Actions

Bug #5447

open

Suricata-Update: Respect rule GID

Added by Jason Ish 2 months ago. Updated 2 months ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
-
Affected Versions:
Effort:
Difficulty:
Label:

Description

Suricata considers the gid when determine the ID of a rule. For example, sid:1; gid:1; is a different rule and does not conflict with sid:1; gid:2;, even tho the sid is the same.

Suricata-Update currently does not respect the gid field at all, so will throw one away, taking the one with the highest rev if provided.

Actions #1

Updated by Jason Ish 2 months ago

  • Assignee changed from Shivani Bhardwaj to OISF Dev
Actions

Also available in: Atom PDF