Modify Suricata defaults

This commit is contained in:
Mike Reeves
2022-09-13 11:29:31 -04:00
parent 74d991da45
commit a32ff6f403

View File

@@ -33,11 +33,11 @@ suricata:
enabled: "yes" enabled: "yes"
interval: 30 interval: 30
outputs: outputs:
- fast: fast:
enabled: "no" enabled: "no"
filename: fast.log filename: fast.log
append: "yes" append: "yes"
- eve-log: eve-log:
enabled: "yes" enabled: "yes"
filetype: regular filetype: regular
filename: /nsm/eve-%Y-%m-%d-%H:%M.json filename: /nsm/eve-%Y-%m-%d-%H:%M.json
@@ -63,50 +63,49 @@ suricata:
metadata: true metadata: true
raw: true raw: true
tagged-packets: "no" tagged-packets: "no"
- unified2-alert: unified2-alert:
enabled: "no" enabled: "no"
- http-log: http-log:
enabled: "no" enabled: "no"
filename: http.log filename: http.log
append: "yes" append: "yes"
- tls-log: tls-log:
enabled: "no" enabled: "no"
filename: tls.log filename: tls.log
append: "yes" append: "yes"
- tls-store: tls-store:
enabled: "no" enabled: "no"
- pcap-log: pcap-log:
enabled: "no" enabled: "no"
filename: log.pcap filename: log.pcap
limit: 1000mb limit: 1000mb
max-files: 2000 max-files: 2000
compression: none compression: none
mode: normal mode: normal
use-stream-depth: "no" use-stream-depth: "no"
honor-pass-rules: "no" honor-pass-rules: "no"
- alert-debug: alert-debug:
enabled: "no" enabled: "no"
filename: alert-debug.log filename: alert-debug.log
append: "yes" append: "yes"
- alert-prelude: alert-prelude:
enabled: "no" enabled: "no"
profile: suricata profile: suricata
log-packet-content: "no" log-packet-content: "no"
log-packet-header: "yes" log-packet-header: "yes"
- stats: stats:
enabled: "yes" enabled: "yes"
filename: stats.log filename: stats.log
append: "yes" append: "yes"
totals: "yes" totals: "yes"
threads: "no" threads: "no"
null-values: "yes" null-values: "yes"
- syslog: syslog:
enabled: "no" enabled: "no"
facility: local5 facility: local5
- drop: drop:
enabled: "no" enabled: "no"
- file-store: file-store:
version: 2 version: 2
enabled: "no" enabled: "no"
xff: xff:
@@ -114,15 +113,15 @@ suricata:
mode: extra-data mode: extra-data
deployment: reverse deployment: reverse
header: X-Forwarded-For header: X-Forwarded-For
- tcp-data: tcp-data:
enabled: "no" enabled: "no"
type: file type: file
filename: tcp-data.log filename: tcp-data.log
- http-body-data: http-body-data:
enabled: "no" enabled: "no"
type: file type: file
filename: http-data.log filename: http-data.log
- lua: lua:
enabled: "no" enabled: "no"
scripts: scripts:
logging: logging:
@@ -398,24 +397,10 @@ suricata:
enabled: "no" enabled: "no"
filename: lock_stats.log filename: lock_stats.log
append: "yes" append: "yes"
pcap-log: pcap-log:
enabled: "no" enabled: "no"
filename: pcaplog_stats.log filename: pcaplog_stats.log
append: "yes" append: "yes"
nfq:
nflog:
- group: 2
buffer-size: 18432
- group: default
qthreshold: 1
qtimeout: 100
max-size: 20000
capture:
netmap:
- interface: eth2
- interface: default
ipfw:
default-rule-path: /etc/suricata/rules default-rule-path: /etc/suricata/rules
rule-files: rule-files:
- all.rules - all.rules