Snort Rules
Overview
Why import Snort rules to IPS?
How to set Snort Signatures
Step 1: Browse to Policy->Assets and edit the Web Application / API asset

Step 2: Make sure the Mode of the Snort Signatures sub-practice is as desired
Step 3: Upload a Snort signature file

Step 4: Enforce Policy
How to PoC the Snort Signatures feature?
Step 1: Create an example Signature file
Step 2: Import the signature file into your policy
Step 3: Trigger the signature
FAQ
Can you help me get started with a few signatures?
Can I use any available Snort Signatures?
How can I write my own signatures?
Writing Snort SignaturesWhat will be the performance impact if I add many Snort signatures?
Is there a maximum number of Snort signatures that can be added?
Is there an API available?
Would any type of existing Snort signatures be compatible?
What are the known limitations?
Last updated
Was this helpful?