Part 4: Rules and Alerting
In the final section of the book, we will discuss Snort rules, including the structure, the syntax, and the details of rule headers and rule options. The chapter on Snort rules will familiarize you with Snort rules, enabling you to understand existing snort rules as well as create new ones. This final part of the book also discusses the alerting and logging capability of Snort 3. The various alert output plugins and their configuration are discussed in the chapter on Alert Subsystem. We will discuss the OpenAppID feature of Snort in Chapter 15. This module enhances the application detection capability of Snort, and it also extends it as a separate package so that it can be updated frequently as needed. The final chapter discusses various miscellaneous topics on Snort 3, including troubleshooting and the migration of a Snort 2 configuration to Snort 3.
This part has the following chapters:
- Chapter 13, Rules
- Chapter 14, Alert Subsystem
- Chapter...