mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
add local.rules and filter.rules to suricata defaults. add extraction.rules, local.rules and filter.rules for suricata metadata
This commit is contained in:
@@ -416,7 +416,6 @@ suricata:
|
||||
enabled: "yes"
|
||||
filename: keyword_perf.log
|
||||
append: "yes"
|
||||
|
||||
prefilter:
|
||||
enabled: "yes"
|
||||
filename: prefilter_perf.log
|
||||
@@ -443,6 +442,8 @@ suricata:
|
||||
default-rule-path: /etc/suricata/rules
|
||||
rule-files:
|
||||
- all.rules
|
||||
- local.rules
|
||||
- filter.rules
|
||||
classification-file: /etc/suricata/classification.config
|
||||
reference-config-file: /etc/suricata/reference.config
|
||||
threshold-file: /etc/suricata/threshold.conf
|
||||
|
||||
@@ -70,3 +70,9 @@ suricata:
|
||||
- flow
|
||||
#- netflow
|
||||
#- metadata
|
||||
profiling:
|
||||
rule-files:
|
||||
- all.rules
|
||||
- extraction.rules
|
||||
- local.rules
|
||||
- filter.rules
|
||||
|
||||
Reference in New Issue
Block a user