Summary
In this chapter, we learned about the application identification feature in Snort, which is known as the OpenAppID feature. We learned about the feature and its use. We discussed the OpenAppID inspector module and its configuration settings. The rule options that makes use of the application identification feature was also discussed.
The chapter also discussed the OpenAppID detector package, which must be downloaded and installed separately from Snort. This package is maintained separately and enjoys large community support. In the next and final chapter, we will discuss some miscellaneous topics, including how to troubleshoot a Snort crash, and how to migrate a Snort 2 configuration to Snort 3.