Move Suricata around

This commit is contained in:
Mike Reeves
2024-03-06 10:35:10 -05:00
parent f836d6a61d
commit 4dfa1a5626
2 changed files with 11 additions and 2 deletions

View File

@@ -1,5 +1,8 @@
suricata:
enabled: False
pcap:
filesize: 1000mb
maxsize: 25
config:
threading:
set-cpu-affinity: "no"
@@ -132,9 +135,7 @@ suricata:
lz4-checksum: "no"
lz4-level: 8
filename: "%n/so-pcap.%t"
limit: "1000mb"
mode: "multi"
max-files: 10
use-stream-depth: "no"
conditional: "all"
dir: "/nsm/suripcap"

View File

@@ -19,6 +19,14 @@ suricata:
multiline: True
title: Classifications
helpLink: suricata.html
pcap:
filesize:
description: Max file size for individual PCAP files written by Suricata. Increasing this number could improve write performance at the expense of pcap retrieval times.
advanced: True
helplink: suricata.html
maxsize:
description: Size in GB for total usage size of PCAP on disk.
helplink: suricata.html
config:
af-packet:
interface: