Hello,
i am using suricata-6.0.3 version , when I start Suricata I will always get below error. And the suricata.log is as attached.suricata.log (90.2 KB)
[ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - pcre with /R (relative) needs preceding match in the same buffer
[ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - can’t use a relative keyword like within/distance with a absolute relative keyword like depth/offset for the same content.
[ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - rule 2836763 mixes keywords with conflicting directions
[ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - “http_header” keyword seen with a sticky buffer still set. Reset sticky buffer with pkt_data before using the modifier.
[ERRCODE: SC_ERR_OFFSET_MISSING_CONTENT(107)] - distance needs preceding content, uricontent option, http_client_body, http_server_body, http_header option, http_raw_header option, http_method option, http_cookie, http_raw_uri, http_stat_msg, http_stat_code, http_user_agent or file_data/dce_stub_data sticky buffer option
[ERRCODE: SC_ERR_RULE_KEYWORD_UNKNOWN(102)] - unknown rule keyword ‘http_raw_cookie’.
[ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - Signature combines packet specific matches (like dsize, flags, ttl) with stream / state matching by matching on app layer proto (like using http_* keywords).
[ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - http_method pattern with trailing space
[ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - can’t use multiple distances for the same content.
[ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit ‘ET.GenericPhish_Adobe’ is checked but not set.
[ERRCODE: SC_WARN_POOR_RULE(276)] - rule 2013479: SYN-only to port(s) 3389:3389 w/o direction
[ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - Unable to find the sm in any of the sm lists