mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
24 lines
952 B
Plaintext
24 lines
952 B
Plaintext
{%- from 'vars/globals.map.jinja' import GLOBALS -%}
|
|
{%- from 'soc/merged.map.jinja' import SOCMERGED -%}
|
|
--suricata-version=7.0.3
|
|
--merged=/opt/so/rules/nids/suri/all.rules
|
|
--output=/nsm/rules/detect-suricata/custom_temp
|
|
--local=/opt/so/rules/nids/suri/local.rules
|
|
{%- if GLOBALS.md_engine == "SURICATA" %}
|
|
--local=/opt/so/rules/nids/suri/extraction.rules
|
|
--local=/opt/so/rules/nids/suri/filters.rules
|
|
{%- endif %}
|
|
--url=http://{{ GLOBALS.manager }}:7788/suricata/emerging-all.rules
|
|
--disable=/opt/so/idstools/etc/disable.conf
|
|
--enable=/opt/so/idstools/etc/enable.conf
|
|
--modify=/opt/so/idstools/etc/modify.conf
|
|
{%- if SOCMERGED.config.server.modules.suricataengine.customRulesets %}
|
|
{%- for ruleset in SOCMERGED.config.server.modules.suricataengine.customRulesets %}
|
|
{%- if 'url' in ruleset %}
|
|
--url={{ ruleset.url }}
|
|
{%- elif 'file' in ruleset %}
|
|
--local={{ ruleset.file }}
|
|
{%- endif %}
|
|
{%- endfor %}
|
|
{%- endif %}
|