Default Snort 3 testing config: Link
Suggested command: snort -c test.lua -r test.pcap
Feature:
- By default, all alerts are printed to STDOUT with alert_full.
- CHECKSUM_MODE off for parsing pcap files wthout dropping packets.
- Verbose mode on.
- Showing debug message of each rule, i.e. fast_pattern matching.
- Disabled all builtin rles.
Snort 3 PCRE reference: Link
Features:
- Removed Snort 3 deprecated options.