View and edit your Snort 3 intrusion policy
This task allows you to customize your Snort 3 intrusion policy by modifying rule groups, security levels, and accessing Cisco-recommended rules to enhance threat detection capabilities.
Snort 3 intrusion policies use a hierarchical rule group structure organized by the MITRE framework. You can drill down to specific rule categories and modify security levels for bulk changes or individual rule actions. The policy editor provides multiple layers, including Group Overrides, Rule Overrides, Recommendations, and Summary views.
Procedure
Step 1 | Choose . | ||
Step 2 | Ensure that the Intrusion Policies tab is chosen.
| ||
Step 3 | Click the Group Overrides layer. This layer lists all the categories of rule groups, in a hierarchical structure. You can drill down to the final leaf rule group under each rule group. ![]() | ||
Step 4 | Click MITRE in the left pane.
![]() | ||
Step 5 | Under Enterprise, click Initial Access to expand it. | ||
Step 6 | Under Initial Access, click Exploit Public-Facing Application, which is the last leaf group.
| ||
Step 7 | Click View Rules in Rule Overrides to view the available rules, their details, and actions. You can change the rule actions for one or multiple rules in the Rule Overrides layer.
| ||
Step 8 | Click the Recommendations layer and then click Start to start using Cisco-recommended rules. You can use the intrusion rule recommendations to target the vulnerabilities that are associated with the host assets detected in the network. For more information, see Generate new Secure Firewall recommendations in Snort 3.
| ||
Step 9 | Click the Summary layer for a holistic view of the current changes to the policy. Based on the rule overrides, security-level changes, and generation of Cisco-recommended rules, you can view the rule distribution of the policy, group overrides, rule overrides, rule recommendations, and additional details to verify your changes.
|
What to do next
Deploy your intrusion policy to detect and log events that are triggered by the Snort rules. See Deploy configuration changes.

