Merge pull request #3058 from Security-Onion-Solutions/delta

Fix intermittent Suricata rules load issue
This commit is contained in:
Mike Reeves
2021-02-20 10:27:13 -05:00
committed by GitHub
6 changed files with 23 additions and 22 deletions

View File

@@ -30,7 +30,7 @@ BASICSURI=2
ZEEKVERSION=ZEEK ZEEKVERSION=ZEEK
# CURCLOSEDAYS= # CURCLOSEDAYS=
# EVALADVANCED=BASIC # EVALADVANCED=BASIC
GRAFANA=1 # GRAFANA=1
# HELIXAPIKEY= # HELIXAPIKEY=
HNMANAGER=10.0.0.0/8,192.168.0.0/16,172.16.0.0/12 HNMANAGER=10.0.0.0/8,192.168.0.0/16,172.16.0.0/12
HNSENSOR=inherit HNSENSOR=inherit
@@ -58,7 +58,7 @@ NODESETUP=NODEBASIC
NSMSETUP=BASIC NSMSETUP=BASIC
NODEUPDATES=MANAGER NODEUPDATES=MANAGER
# OINKCODE= # OINKCODE=
OSQUERY=1 # OSQUERY=1
# PATCHSCHEDULEDAYS= # PATCHSCHEDULEDAYS=
# PATCHSCHEDULEHOURS= # PATCHSCHEDULEHOURS=
PATCHSCHEDULENAME=auto PATCHSCHEDULENAME=auto
@@ -71,8 +71,8 @@ RULESETUP=ETOPEN
# SOREMOTEPASS1=onionuser # SOREMOTEPASS1=onionuser
# SOREMOTEPASS2=onionuser # SOREMOTEPASS2=onionuser
STRELKA=1 STRELKA=1
THEHIVE=1 # THEHIVE=1
WAZUH=1 # WAZUH=1
WEBUSER=onionuser@somewhere.invalid WEBUSER=onionuser@somewhere.invalid
WEBPASSWD1=0n10nus3r WEBPASSWD1=0n10nus3r
WEBPASSWD2=0n10nus3r WEBPASSWD2=0n10nus3r

View File

@@ -30,7 +30,7 @@ BASICSURI=2
ZEEKVERSION=ZEEK ZEEKVERSION=ZEEK
# CURCLOSEDAYS= # CURCLOSEDAYS=
# EVALADVANCED=BASIC # EVALADVANCED=BASIC
GRAFANA=1 # GRAFANA=1
# HELIXAPIKEY= # HELIXAPIKEY=
HNMANAGER=10.0.0.0/8,192.168.0.0/16,172.16.0.0/12 HNMANAGER=10.0.0.0/8,192.168.0.0/16,172.16.0.0/12
HNSENSOR=inherit HNSENSOR=inherit
@@ -57,7 +57,7 @@ NODESETUP=NODEBASIC
NSMSETUP=BASIC NSMSETUP=BASIC
NODEUPDATES=MANAGER NODEUPDATES=MANAGER
# OINKCODE= # OINKCODE=
OSQUERY=1 # OSQUERY=1
# PATCHSCHEDULEDAYS= # PATCHSCHEDULEDAYS=
# PATCHSCHEDULEHOURS= # PATCHSCHEDULEHOURS=
PATCHSCHEDULENAME=auto PATCHSCHEDULENAME=auto
@@ -70,8 +70,8 @@ RULESETUP=ETOPEN
# SOREMOTEPASS1=onionuser # SOREMOTEPASS1=onionuser
# SOREMOTEPASS2=onionuser # SOREMOTEPASS2=onionuser
STRELKA=1 STRELKA=1
THEHIVE=1 # THEHIVE=1
WAZUH=1 # WAZUH=1
WEBUSER=onionuser@somewhere.invalid WEBUSER=onionuser@somewhere.invalid
WEBPASSWD1=0n10nus3r WEBPASSWD1=0n10nus3r
WEBPASSWD2=0n10nus3r WEBPASSWD2=0n10nus3r

View File

@@ -30,7 +30,7 @@ BASICSURI=2
ZEEKVERSION=ZEEK ZEEKVERSION=ZEEK
# CURCLOSEDAYS= # CURCLOSEDAYS=
# EVALADVANCED=BASIC # EVALADVANCED=BASIC
GRAFANA=1 # GRAFANA=1
# HELIXAPIKEY= # HELIXAPIKEY=
HNMANAGER=10.0.0.0/8,192.168.0.0/16,172.16.0.0/12 HNMANAGER=10.0.0.0/8,192.168.0.0/16,172.16.0.0/12
HNSENSOR=inherit HNSENSOR=inherit
@@ -57,7 +57,7 @@ NODESETUP=NODEBASIC
NSMSETUP=BASIC NSMSETUP=BASIC
NODEUPDATES=MANAGER NODEUPDATES=MANAGER
# OINKCODE= # OINKCODE=
OSQUERY=1 # OSQUERY=1
# PATCHSCHEDULEDAYS= # PATCHSCHEDULEDAYS=
# PATCHSCHEDULEHOURS= # PATCHSCHEDULEHOURS=
PATCHSCHEDULENAME=auto PATCHSCHEDULENAME=auto
@@ -70,8 +70,8 @@ RULESETUP=ETOPEN
# SOREMOTEPASS1=onionuser # SOREMOTEPASS1=onionuser
# SOREMOTEPASS2=onionuser # SOREMOTEPASS2=onionuser
STRELKA=1 STRELKA=1
THEHIVE=1 # THEHIVE=1
WAZUH=1 # WAZUH=1
WEBUSER=onionuser@somewhere.invalid WEBUSER=onionuser@somewhere.invalid
WEBPASSWD1=0n10nus3r WEBPASSWD1=0n10nus3r
WEBPASSWD2=0n10nus3r WEBPASSWD2=0n10nus3r

View File

@@ -30,7 +30,7 @@ BASICSURI=2
ZEEKVERSION=ZEEK ZEEKVERSION=ZEEK
# CURCLOSEDAYS= # CURCLOSEDAYS=
# EVALADVANCED=BASIC # EVALADVANCED=BASIC
GRAFANA=1 # GRAFANA=1
# HELIXAPIKEY= # HELIXAPIKEY=
HNMANAGER=10.0.0.0/8,192.168.0.0/16,172.16.0.0/12 HNMANAGER=10.0.0.0/8,192.168.0.0/16,172.16.0.0/12
HNSENSOR=inherit HNSENSOR=inherit
@@ -57,11 +57,11 @@ NODESETUP=NODEBASIC
NSMSETUP=BASIC NSMSETUP=BASIC
NODEUPDATES=MANAGER NODEUPDATES=MANAGER
# OINKCODE= # OINKCODE=
OSQUERY=1 # OSQUERY=1
# PATCHSCHEDULEDAYS= # PATCHSCHEDULEDAYS=
# PATCHSCHEDULEHOURS= # PATCHSCHEDULEHOURS=
PATCHSCHEDULENAME=auto PATCHSCHEDULENAME=auto
#PLAYBOOK=1 # PLAYBOOK=1
# REDIRECTHOST= # REDIRECTHOST=
REDIRECTINFO=IP REDIRECTINFO=IP
RULESETUP=ETOPEN RULESETUP=ETOPEN
@@ -70,8 +70,8 @@ RULESETUP=ETOPEN
# SOREMOTEPASS1=onionuser # SOREMOTEPASS1=onionuser
# SOREMOTEPASS2=onionuser # SOREMOTEPASS2=onionuser
STRELKA=1 STRELKA=1
THEHIVE=1 # THEHIVE=1
WAZUH=1 # WAZUH=1
WEBUSER=onionuser@somewhere.invalid WEBUSER=onionuser@somewhere.invalid
WEBPASSWD1=0n10nus3r WEBPASSWD1=0n10nus3r
WEBPASSWD2=0n10nus3r WEBPASSWD2=0n10nus3r

View File

@@ -30,7 +30,7 @@ BASICSURI=2
ZEEKVERSION=ZEEK ZEEKVERSION=ZEEK
# CURCLOSEDAYS= # CURCLOSEDAYS=
# EVALADVANCED=BASIC # EVALADVANCED=BASIC
GRAFANA=1 # GRAFANA=1
# HELIXAPIKEY= # HELIXAPIKEY=
HNMANAGER=10.0.0.0/8,192.168.0.0/16,172.16.0.0/12 HNMANAGER=10.0.0.0/8,192.168.0.0/16,172.16.0.0/12
HNSENSOR=inherit HNSENSOR=inherit
@@ -57,11 +57,11 @@ NODESETUP=NODEBASIC
NSMSETUP=BASIC NSMSETUP=BASIC
NODEUPDATES=MANAGER NODEUPDATES=MANAGER
# OINKCODE= # OINKCODE=
OSQUERY=1 # OSQUERY=1
# PATCHSCHEDULEDAYS= # PATCHSCHEDULEDAYS=
# PATCHSCHEDULEHOURS= # PATCHSCHEDULEHOURS=
PATCHSCHEDULENAME=auto PATCHSCHEDULENAME=auto
#PLAYBOOK=1 # PLAYBOOK=1
# REDIRECTHOST= # REDIRECTHOST=
REDIRECTINFO=IP REDIRECTINFO=IP
RULESETUP=ETOPEN RULESETUP=ETOPEN
@@ -70,8 +70,8 @@ RULESETUP=ETOPEN
# SOREMOTEPASS1=onionuser # SOREMOTEPASS1=onionuser
# SOREMOTEPASS2=onionuser # SOREMOTEPASS2=onionuser
STRELKA=1 STRELKA=1
THEHIVE=1 # THEHIVE=1
WAZUH=1 # WAZUH=1
WEBUSER=onionuser@somewhere.invalid WEBUSER=onionuser@somewhere.invalid
WEBPASSWD1=0n10nus3r WEBPASSWD1=0n10nus3r
WEBPASSWD2=0n10nus3r WEBPASSWD2=0n10nus3r

View File

@@ -891,6 +891,7 @@ create_local_nids_rules() {
# Create a local.rules file so it doesn't get blasted on updates # Create a local.rules file so it doesn't get blasted on updates
mkdir -p /opt/so/saltstack/local/salt/idstools mkdir -p /opt/so/saltstack/local/salt/idstools
echo "# Custom Suricata rules go in this file" > /opt/so/saltstack/local/salt/idstools/local.rules echo "# Custom Suricata rules go in this file" > /opt/so/saltstack/local/salt/idstools/local.rules
salt-run fileserver.clear_file_list_cache
} }
create_repo() { create_repo() {