From 6cf0a0bb42f0142b52218ef346e6df9d8386eecc Mon Sep 17 00:00:00 2001 From: Mike Reeves Date: Mon, 22 Jul 2024 10:19:34 -0400 Subject: [PATCH 1/2] Update so-rule-update --- salt/idstools/tools/sbin_jinja/so-rule-update | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/salt/idstools/tools/sbin_jinja/so-rule-update b/salt/idstools/tools/sbin_jinja/so-rule-update index 4ea79c94e..9ac09ed15 100755 --- a/salt/idstools/tools/sbin_jinja/so-rule-update +++ b/salt/idstools/tools/sbin_jinja/so-rule-update @@ -23,9 +23,9 @@ if [[ ! "`pidof -x $(basename $0) -o %PPID`" ]]; then {%- if not GLOBALS.airgap %} # Download the rules from the internet {%- if IDSTOOLSMERGED.config.ruleset == 'ETOPEN' %} - docker exec so-idstools idstools-rulecat -v --suricata-version 6.0 -o /nsm/rules/suricata/ --merged=/nsm/rules/suricata/emerging-all.rules --force + docker exec so-idstools idstools-rulecat -v --suricata-version 7.0.3 -o /nsm/rules/suricata/ --merged=/nsm/rules/suricata/emerging-all.rules --force {%- elif IDSTOOLSMERGED.config.ruleset == 'ETPRO' %} - docker exec so-idstools idstools-rulecat -v --suricata-version 6.0 -o /nsm/rules/suricata/ --merged=/nsm/rules/suricata/emerging-all.rules --force --etpro={{ IDSTOOLSMERGED.config.oinkcode }} + docker exec so-idstools idstools-rulecat -v --suricata-version 7.0.3 -o /nsm/rules/suricata/ --merged=/nsm/rules/suricata/emerging-all.rules --force --etpro={{ IDSTOOLSMERGED.config.oinkcode }} {%- endif %} {%- endif %} From af0425b8f1c10b5fb099e7d8fce466f7a5d21a71 Mon Sep 17 00:00:00 2001 From: Mike Reeves Date: Mon, 22 Jul 2024 10:20:30 -0400 Subject: [PATCH 2/2] Update rulecat.conf --- salt/idstools/etc/rulecat.conf | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/salt/idstools/etc/rulecat.conf b/salt/idstools/etc/rulecat.conf index db78cec29..e4ec611db 100644 --- a/salt/idstools/etc/rulecat.conf +++ b/salt/idstools/etc/rulecat.conf @@ -1,6 +1,6 @@ {%- from 'vars/globals.map.jinja' import GLOBALS -%} {%- from 'soc/merged.map.jinja' import SOCMERGED -%} ---suricata-version=6.0 +--suricata-version=7.0.3 --merged=/opt/so/rules/nids/suri/all.rules --output=/nsm/rules/detect-suricata/custom_temp --local=/opt/so/rules/nids/suri/local.rules @@ -20,4 +20,4 @@ --local={{ ruleset.file }} {%- endif %} {%- endfor %} -{%- endif %} \ No newline at end of file +{%- endif %}