diff --git a/salt/manager/tools/sbin_jinja/so-yara-update b/salt/manager/tools/sbin_jinja/so-yara-update index ae2a0d97c..2cb59056c 100755 --- a/salt/manager/tools/sbin_jinja/so-yara-update +++ b/salt/manager/tools/sbin_jinja/so-yara-update @@ -18,6 +18,8 @@ SORULEDIR=/nsm/rules/yara OUTPUTDIR=/opt/so/saltstack/local/salt/strelka/rules mkdir -p $OUTPUTDIR +# remove all rules prior to copy so we can clear out old rules +rm -f $OUTPUTDIR/* for i in $(find $SORULEDIR -name "*.yar" -o -name "*.yara"); do rule_name=$(echo $i | awk -F '/' '{print $NF}')