This sections explains how to fix Snort rules that fail to convert. Rules that fail to convert after import are set to Failed in the Validation Result column.
Perform the following steps to troubleshoot a failed rule:
Double click on the failed rule in Custom Attack Editor. The Edit Snort Attack window opens.
Click
to validate the rule.For example, in the image, the validation error is related to an incorrect input type in the rule.
.jpg)
Update the rule to resolve the error.
Click
to validate the rule..jpg)
If the rule is validated successfully, a Success pop-up appears. Click OK.
Click Save to save the changes you made.
The rule is now converted to Trellix IPS's format and stored in the Manager database.
Note
After the rules are corrected, you can use the Test Compile feature to check the validity and compatibility. To validate the attacks, select the required attacks, right-click and select Test Compile.