rule_url=https://www.snort.org/reg-rules/|snortrules-snapshot.tar.gz|< your oinkcode> rule_url=https://www.snort.org/reg-rules/|opensource.gz|< your oinkcode> rule_url=https://rules.emergingthreatspro.com/|emerging.rules.tar.gz|open-nogpl ignore=deleted.rules,experimental.rules,local.rules temp_path=/tmp rule_path=/etc/snort/rules/snort.rules local_rules=/etc/snort/rules/local.rules sid_msg=/etc/snort/sid-msg.map sid_msg_version=1 sid_changelog=/var/log/sid_changes.log sorule_path=/usr/lib/snort_dynamicrules/ snort_path=/usr/sbin/snort config_path=/etc/snort/snort.conf black_list=/etc/snort/rules/iplists/default.blacklist IPRVersion=/etc/snort/rules/iplists sostub_path=/etc/snort/rules/so_rules.rules distro=Ubuntu-12.04 backup_file=/tmp/pp_backup pid_path=/var/run/snort_eth0.pid snort_version=2.9.2.3 # enablesid=/usr/local/etc/snort/enablesid.conf # dropsid=/usr/local/etc/snort/dropsid.conf # disablesid=/usr/local/etc/snort/disablesid.conf # modifysid=/usr/local/etc/snort/modifysid.conf # latest version so far ; modify it according to your running version or else it won't work version=0.7.0