run> cat dump.xml | get_urls >local.rules 2>get_urls.log run> cat dump.xml | get_domains >>local.rules 2>get_domains.log run> cat dump.xml | get_https >>local.rules 2>get_https.log run> cat dump.xml | get_ips >>local.rules 2>get_ips.log
2. ΠΊΠΎΠΏΠΈΡΡΠ΅ΠΌ "local.rules" Π² ΠΊΠ°ΡΠ°Π»ΠΎΠ³ Π½Π°ΡΡΡΠΎΠ΅ΠΊ Π΄Π»Ρ ΡΠ½ΠΎΡΡΠ°. Π£ ΠΌΠ΅Π½Ρ, Π½Π°ΠΏΡΠΈΠΌΠ΅Ρ, Π² /etc/snort/rules/local.rules
run> snort -N -D -c /etc/snort/snort.conf -i enp5s1 -P 65535