Project

General

Profile

Actions

Bug #9195

closed

Suricata (latest): very large number of rules cause errors due to unknown reference keys on Rebuild with Interface SID Management List Assignments

Added by P L almost 6 years ago. Updated over 5 years ago.

Status:
Resolved
Priority:
Very High
Assignee:
-
Category:
Suricata
Target version:
-
Start date:
12/13/2018
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Affected Version:
Affected Plus Version:
Affected Architecture:

Description

I receive a very (very) large number of these kinds of errors in the Suricata logs (and system logs) related to reference keys "bid" and "md5".

12/12/2018 -- 16:31:45 - <Error> -- [ERRCODE: SC_ERR_REFERENCE_UNKNOWN(150)] - unknown reference key "bid". Supported keys are defined in reference.config file. Please have a look at the conf param "reference-config-file"
12/12/2018 -- 16:31:45 - <Error> -- [ERRCODE: SC_ERR_REFERENCE_UNKNOWN(150)] - unknown reference key "md5". Supported keys are defined in reference.config file. Please have a look at the conf param "reference-config-file"

Today, there are new reference keys with errors (e.g., unknown rule keyword 'http_raw_cookie').


Files

system.log (500 KB) system.log P L, 12/13/2018 12:46 AM
suricata.log (2 MB) suricata.log P L, 12/13/2018 12:47 AM
Actions

Also available in: Atom PDF