Thanks For Downloading!
Review the documentation below and follow any custom installation steps. If no install steps are listed, most Splunk Apps and Add-ons can be installed as follows:
Unix/Linux: Decompress the downloaded file using a tool like
Provides visibility into Snort/PulledPork .rules files and Snort VRT rule documentation for tuning and general reference. See http://eyeis.net/2012/08/ids-rule-reference-for-splunk-1-0/ for screenshots.
Versions and Release Notes
Version 1.1 (current version - updated Aug 23, 2012)
1.1 - Performance improvements
Just installed this and came up with the following error:
WARN IniFile - /opt/splunk/etc/apps/ids_ref/default/props.conf, line 9: Cannot parse into key-value pair: aq>[^;]+)
It seems there's a line break at the end of that line that shouldn't be there. Simply appending
to line 8 and deleting the same from line 9 fixed it :)
reviewed 17 Mar, 13:28
accept rate: 0%