tips:suricata-eve-unixsocket
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revisionNext revisionBoth sides next revision | ||
tips:suricata-eve-unixsocket [2020/08/27 19:05] – [3. Installing Emerging Threat Rules 5.0] navaneeth | tips:suricata-eve-unixsocket [2020/09/10 16:28] – [2. Installing Suricata version 5.0] veera | ||
---|---|---|---|
Line 20: | Line 20: | ||
apt-get install suricata | apt-get install suricata | ||
</ | </ | ||
+ | |||
+ | |||
+ | ===== Updating with latest ruleset ===== | ||
+ | |||
+ | Use the following command to update the latest emerging-threats ruleset | ||
+ | |||
+ | < | ||
+ | |||
+ | suricata-update puts the combined rules in ''/ | ||
+ | |||
+ | < | ||
+ | |||
+ | |||
+ | |||
+ | |||
+ | |||
+ | |||
==== 3. Installing Emerging Threat Rules 5.0 ==== | ==== 3. Installing Emerging Threat Rules 5.0 ==== | ||
Line 46: | Line 63: | ||
</ | </ | ||
< | < | ||
- | |||
- | * And, also disable the ' | ||
- | |||
- | < | ||
- | # a line based alerts log similar to Snort' | ||
- | - fast: | ||
- | enabled: no | ||
- | filename: fast.log | ||
- | append: yes | ||
- | #filetype: regular # ' | ||
| | ||
Line 62: | Line 69: | ||
* Click on 'More options' | * Click on 'More options' | ||
* You will find a Dialog box with command line to install Suricata as below. | * You will find a Dialog box with command line to install Suricata as below. | ||
+ | * Cut and paste the command shown into a terminal to start suricata | ||
< | < | ||
Line 69: | Line 77: | ||
{{: | {{: | ||
- | <note important> | + | ==== 6. Viewing Alerts |
- | + | ||
- | {{: | + | |
- | + | ||
- | ==== 6. Updating with latest rules ==== | + | |
- | + | ||
- | If you have already installed suricata and you want to update with the latest rules. Use the following command. | + | |
- | + | ||
- | < | + | |
- | + | ||
- | + | ||
+ | {{: | ||
tips/suricata-eve-unixsocket.txt · Last modified: 2020/09/28 17:22 by navaneeth