mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
add default ruleset
This commit is contained in:
@@ -1586,6 +1586,14 @@ soc:
|
||||
insecureSkipVerify: false
|
||||
readOnly: true
|
||||
deleteUnreferenced: true
|
||||
- name: ABUSECH-SSLBL
|
||||
deleteUnreferenced: true
|
||||
description: 'Abuse.ch SSL Blacklist'
|
||||
enabled: false
|
||||
license: CC0-1.0
|
||||
readOnly: true
|
||||
sourcePath: https://sslbl.abuse.ch/blacklist/sslblacklist_tls_cert.tar.gz
|
||||
sourceType: url
|
||||
- name: local-rules
|
||||
id: local-rules
|
||||
description: "Local custom rules from files (*.rules) in a directory on the filesystem"
|
||||
|
||||
@@ -159,7 +159,7 @@ surithresholding:
|
||||
- source: salt://suricata/files/threshold.conf
|
||||
- user: 940
|
||||
- group: 940
|
||||
- contents: 'This file is managed by Security Onion. Do not modify by hand.'
|
||||
- onlyif: salt://suricata/files/threshold.conf
|
||||
|
||||
suriclassifications:
|
||||
file.managed:
|
||||
|
||||
Reference in New Issue
Block a user