Before you save the Snort Custom Attacks to the database, you can also specify the Sensor type. For example, if you choose NS-series as the Sensor type for an attack, then this attack definition is relevant only to the NS-series Sensors of the corresponding admin domain. So only the NS-series Sensors inspect the traffic for this particular attack definition. Even when you apply the same policy to a Virtual Sensor, it does not check for this attack.
Steps:
Go to the corresponding tab in the Custom Attack Editor.
Verify that the rules that you want to be published in the rulesets are in the Published state. If not, you can click on the attack and select Published.
Verify the Target Device to which the Snort Custom Attack should be applied to.
For example, if you select NS-series, only the NS-series Sensors in the current admin domain inspect traffic for this attack.
Click Save.
The qualified rules are saved in the database and the corresponding policies are updated with these attacks. You can view the progress in the bottom part of the Custom Attack Editor.
You need to update the Sensors for the saved attacks to be detected.
You can also verify if the attacks are published in the policies.
From the Resource Tree, select Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS.
Double-click on one of the All Inclusive policies; for example, you can open the Default Testing policy.
Click Attack Definitions tab.
Sort the attacks based on Name and verify if the Snort rules have been published.