You can use the Snort Variables feature to view the names and values of the variables and classification types that are available in the Manager database.
This feature enables you to the following:
Check if you are using valid macros and classification types when you create or import a Snort Custom Attack. (You cannot create a Snort Custom Attack that contains an undefined macro or classification type. If you import a rule with an undefined macro or classification type, it will fail validation.)
Verify if a macro or classification type that you want to define is already available.
Verify if an import of macro or classification types was successful.
Add or delete macros of a classification type.
To view the names of the macros and classification types in the Manager:
Steps:
In the Custom Attack Editor from the Snort Format tab, click Snort Variables.
The Snort Variables dialog opens.
.png)
Import variables
To import all the listed variables, classification types, and references:
Click Actions → Import.
This imports the variables to the Manager client.
Click Save.
This imports the variables to the Manager server. The Manager automatically detects the type of the following types of variable at the time of import:
IP address
Port
Any
Note
If the Manager cannot determine the type of the variable, the variable is listed as UNDEFINED.
You can specify the value of the variable as any in which case the variable can be used as an IP address as well as a port number.
If any of the values of a variable is any or ![any], the entire value of the variable is considered as any.
Tip
As a best practice if you change the value of any variable, always re-evaluate the rules before saving the attack changes.
Modify variables
To modify a variable:
Click on Remove icon for the variable.
Enter the new value in Value.
Click Add.
Click Save.
After you click Save, the updated value of the variable is saved. However, the updated value of the variable is not reflected in the rules that use the variable. To update the value of the variable in all the rules, you should re-evaluate the rules. To re-evaluate the rules:
In the Snort Variables dialog, click Actions → Re-Evaluate Rules.
Click Save to save the updated Snort rules.
Note
When you re-evaluate the rules, all the rules listed in the Snort Format tab are submitted for re-evaluation and not just the failed ones.
Re-submitting rules with the current variables and classification types
In the Snort Variables dialog, click Actions → Re-Evaluate Rules. if you want the Manager to reevaluate all the rules on the Snort Format tab to the currently available variables.
This feature is useful if you had:
Imported the rules before you had defined the variables. If you resubmit the rules now, the ones that failed to evaluate because of invalid variables get successfully evaluated.
Modified the values of variables
Restore default variables and classification types
To restore all the listed variables, classification types, and references:
Click Actions → Restore Default Variables.
This restores the details to the Manager client.
Click Save.
This restores the details from the Manager server.
Deleting variables and classification types from the Manager
To delete all the listed variables, classification types, and references from the Manager:
Click Actions → Delete All Variables.
This deletes the details from the Manager client.
Click Save.
This deletes the details from the Manager server.