Snort 3 rule changes in LSP updates

Snort 3 rule changes in LSP updates are modifications to system-defined intrusion rules that

  • replace existing rules with new rules for better detection capabilities,

  • combine multiple rules into a single rule or expand a single rule into multiple rules when better detection is possible, and

  • remove existing system-defined rules for better management as part of the LSP update.

To get notifications for changes to any overridden system-defined rules during LSP updates, ensure that the Retain user overrides for deleted Snort 3 rules check box is checked.

To navigate to the Retain user overrides for deleted Snort 3 rules check box, click Administration > Configuration > Intrusion Policy Preferences.

By default this check box is checked. When this check box is checked, the system retains the rule overrides in the new replacement rules that are added as a part of the LSP update. The notifications are shown in the Tasks tab under the Notifications icon that is located next to Notification.