mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
fix pcap paths
This commit is contained in:
@@ -23,6 +23,9 @@ so-sensoroni:
|
|||||||
- /opt/so/conf/sensoroni/sensoroni.json:/opt/sensoroni/sensoroni.json:ro
|
- /opt/so/conf/sensoroni/sensoroni.json:/opt/sensoroni/sensoroni.json:ro
|
||||||
- /opt/so/conf/sensoroni/analyzers:/opt/sensoroni/analyzers:rw
|
- /opt/so/conf/sensoroni/analyzers:/opt/sensoroni/analyzers:rw
|
||||||
- /opt/so/log/sensoroni:/opt/sensoroni/logs:rw
|
- /opt/so/log/sensoroni:/opt/sensoroni/logs:rw
|
||||||
|
{% if GLOBALS.pcap_engine == "SURICATA" %}
|
||||||
|
- /nsm/suripcap/:/nsm/suripcap:rw
|
||||||
|
{% endif %}
|
||||||
{% if DOCKER.containers['so-sensoroni'].custom_bind_mounts %}
|
{% if DOCKER.containers['so-sensoroni'].custom_bind_mounts %}
|
||||||
{% for BIND in DOCKER.containers['so-sensoroni'].custom_bind_mounts %}
|
{% for BIND in DOCKER.containers['so-sensoroni'].custom_bind_mounts %}
|
||||||
- {{ BIND }}
|
- {{ BIND }}
|
||||||
|
|||||||
@@ -137,7 +137,7 @@ suricata:
|
|||||||
max-files: 10
|
max-files: 10
|
||||||
use-stream-depth: "no"
|
use-stream-depth: "no"
|
||||||
conditional: "all"
|
conditional: "all"
|
||||||
dir: "/nsm/pcap"
|
dir: "/nsm/suripcap"
|
||||||
alert-debug:
|
alert-debug:
|
||||||
enabled: "no"
|
enabled: "no"
|
||||||
alert-prelude:
|
alert-prelude:
|
||||||
|
|||||||
@@ -36,7 +36,7 @@ so-suricata:
|
|||||||
- /nsm/suricata/extracted:/var/log/suricata//filestore:rw
|
- /nsm/suricata/extracted:/var/log/suricata//filestore:rw
|
||||||
- /opt/so/conf/suricata/bpf:/etc/suricata/bpf:ro
|
- /opt/so/conf/suricata/bpf:/etc/suricata/bpf:ro
|
||||||
{% if GLOBALS.pcap_engine == "SURICATA" %}
|
{% if GLOBALS.pcap_engine == "SURICATA" %}
|
||||||
- /nsm/suripcap/:/nsm/pcap:rw
|
- /nsm/suripcap/:/nsm/suripcap:rw
|
||||||
{% endif %}
|
{% endif %}
|
||||||
{% if DOCKER.containers['so-suricata'].custom_bind_mounts %}
|
{% if DOCKER.containers['so-suricata'].custom_bind_mounts %}
|
||||||
{% for BIND in DOCKER.containers['so-suricata'].custom_bind_mounts %}
|
{% for BIND in DOCKER.containers['so-suricata'].custom_bind_mounts %}
|
||||||
|
|||||||
Reference in New Issue
Block a user