That helps if it's a Snort/Sourcefire rule, but not if it's a bleeding or local rule.
-----Original Message-----
From: Joel Esler []
Sent: Wednesday, September 21, 2005 11:32 AM
To: Humes, David G.
Subject: Re: [Secureideas-base-user] Display Snort SIDs in BASE

If you click on the "snort" link, next to the alert.  The Snort link has the sid number.


On Sep 21, 2005, at 11:17 AM, Humes, David G. wrote:

I was wondering about the possibility of including an option in BASE to display the SID for each alert assuming one exists.  I'm using Oinkmaster to maintain my rules, and it would be handy to have the SIDs right in BASE when tuning the rules rather than having to grep the rules files for the SIDs.  A column between the Time and Triggered Signature columns in the Meta data would seem to be the right place.  Is there any way to do this now?  Any thoughts?