<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: API For Adding/Removing Snort Signatures and Indicators in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/api-for-adding-removing-snort-signatures-and-indicators/m-p/3865397#M925501</link>
    <description>&lt;P&gt;I have been looking to solve for this as well.&amp;nbsp; I found that if you know the UUID of the signature, you can perform a GET and you receive some info.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;GET successful. Response data --&amp;gt;&lt;BR /&gt;{&lt;BR /&gt;"description": "GID: 1, SID: 978",&lt;BR /&gt;"id": "e7e162f5-aee8-4ec1-93a1-4ec5483f15d3",&lt;BR /&gt;"links": {&lt;BR /&gt;"self": "&lt;A href="https://x.x.x.x/api/fmc_config/v1/domain/e276abec-e0f2-11e3-8169-6d9ed49b625f/policy/intrusionpolicies/" target="_blank"&gt;https://x.x.x.x/api/fmc_config/v1/domain/e276abec-e0f2-11e3-8169-6d9ed49b625f/policy/intrusionpolicies/&lt;/A&gt;&lt;STRONG&gt;e7e162f5-aee8-4ec1-93a1-4ec5483f15d3&lt;/STRONG&gt;"&lt;BR /&gt;},&lt;BR /&gt;"metadata": {&lt;BR /&gt;"domain": {&lt;BR /&gt;"id": "e276abec-e0f2-11e3-8169-6d9ed49b625f",&lt;BR /&gt;"name": "Global",&lt;BR /&gt;"type": "domain"&lt;BR /&gt;},&lt;BR /&gt;"lastUser": {&lt;BR /&gt;"id": "68d03c42-d9bd-11dc-89f2-b7961d42c462",&lt;BR /&gt;"name": "admin",&lt;BR /&gt;"type": "user"&lt;BR /&gt;},&lt;BR /&gt;"readOnly": {&lt;BR /&gt;"state": false&lt;BR /&gt;},&lt;BR /&gt;"timestamp": 1557266680&lt;BR /&gt;},&lt;BR /&gt;"name": "\"SERVER-IIS ASP contents view\"",&lt;BR /&gt;"type": "idsrule"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I plan to explore this further when time allows.&amp;nbsp; Please share any progress you may have made on this matter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 30 May 2019 19:47:03 GMT</pubDate>
    <dc:creator>babd00n</dc:creator>
    <dc:date>2019-05-30T19:47:03Z</dc:date>
    <item>
      <title>API For Adding/Removing Snort Signatures and Indicators</title>
      <link>https://community.cisco.com/t5/network-security/api-for-adding-removing-snort-signatures-and-indicators/m-p/3850923#M925500</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a REST API (e.g. for Firepower Managment Console, etc) that will allow you to add/remove custom Snort signatures/IDS Rules on a Firepower IDS? What about IPs to detect/block on? The closest I found was "PUT Inidicator" for the Firepower Managment Center REST API:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/640/api/REST/Firepower_Management_Center_REST_API_Quick_Start_Guide_640/Objects_In_The_REST_API.html#reference_lmt_2xf_bcb" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/640/api/REST/Firepower_Management_Center_REST_API_Quick_Start_Guide_640/Objects_In_The_REST_API.html#reference_lmt_2xf_bcb&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wasn't sure though what exactly that did, and I could not find anything like that related to Snort.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:06:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/api-for-adding-removing-snort-signatures-and-indicators/m-p/3850923#M925500</guid>
      <dc:creator>BlindSquirrel</dc:creator>
      <dc:date>2020-02-21T17:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: API For Adding/Removing Snort Signatures and Indicators</title>
      <link>https://community.cisco.com/t5/network-security/api-for-adding-removing-snort-signatures-and-indicators/m-p/3865397#M925501</link>
      <description>&lt;P&gt;I have been looking to solve for this as well.&amp;nbsp; I found that if you know the UUID of the signature, you can perform a GET and you receive some info.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;GET successful. Response data --&amp;gt;&lt;BR /&gt;{&lt;BR /&gt;"description": "GID: 1, SID: 978",&lt;BR /&gt;"id": "e7e162f5-aee8-4ec1-93a1-4ec5483f15d3",&lt;BR /&gt;"links": {&lt;BR /&gt;"self": "&lt;A href="https://x.x.x.x/api/fmc_config/v1/domain/e276abec-e0f2-11e3-8169-6d9ed49b625f/policy/intrusionpolicies/" target="_blank"&gt;https://x.x.x.x/api/fmc_config/v1/domain/e276abec-e0f2-11e3-8169-6d9ed49b625f/policy/intrusionpolicies/&lt;/A&gt;&lt;STRONG&gt;e7e162f5-aee8-4ec1-93a1-4ec5483f15d3&lt;/STRONG&gt;"&lt;BR /&gt;},&lt;BR /&gt;"metadata": {&lt;BR /&gt;"domain": {&lt;BR /&gt;"id": "e276abec-e0f2-11e3-8169-6d9ed49b625f",&lt;BR /&gt;"name": "Global",&lt;BR /&gt;"type": "domain"&lt;BR /&gt;},&lt;BR /&gt;"lastUser": {&lt;BR /&gt;"id": "68d03c42-d9bd-11dc-89f2-b7961d42c462",&lt;BR /&gt;"name": "admin",&lt;BR /&gt;"type": "user"&lt;BR /&gt;},&lt;BR /&gt;"readOnly": {&lt;BR /&gt;"state": false&lt;BR /&gt;},&lt;BR /&gt;"timestamp": 1557266680&lt;BR /&gt;},&lt;BR /&gt;"name": "\"SERVER-IIS ASP contents view\"",&lt;BR /&gt;"type": "idsrule"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I plan to explore this further when time allows.&amp;nbsp; Please share any progress you may have made on this matter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2019 19:47:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/api-for-adding-removing-snort-signatures-and-indicators/m-p/3865397#M925501</guid>
      <dc:creator>babd00n</dc:creator>
      <dc:date>2019-05-30T19:47:03Z</dc:date>
    </item>
  </channel>
</rss>

