tips:suricata-eve-unixsocket
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revisionNext revisionBoth sides next revision | ||
tips:suricata-eve-unixsocket [2020/08/27 19:10] – [5. Starting Suricata] navaneeth | tips:suricata-eve-unixsocket [2020/09/10 17:45] – [3. Installing Emerging Threat Rules 5.0] navaneeth | ||
---|---|---|---|
Line 21: | Line 21: | ||
</ | </ | ||
- | ==== 3. Installing Emerging Threat Rules 5.0 ==== | + | |
+ | ===== Updating with latest ruleset | ||
+ | |||
+ | Use the following command to update the latest emerging-threats ruleset | ||
+ | |||
+ | < | ||
+ | |||
+ | suricata-update puts the combined rules in ''/ | ||
+ | |||
+ | < | ||
+ | |||
+ | |||
+ | |||
- | * You have to install the Emerging Threats Community which are a set of rules that trisul will listen to. | ||
- | * Download and install Emerging Threats Open rules into /// | ||
- | < | ||
- | #wget https:// | ||
- | #tar xf emerging.rules.tar.gz | ||
- | </ | ||
- | <note important> | ||
==== 4. Enabling EVE_unix Socket ==== | ==== 4. Enabling EVE_unix Socket ==== | ||
Line 60: | Line 66: | ||
{{: | {{: | ||
- | ==== 7. Viewing Alerts ==== | + | ==== 6. Viewing Alerts ==== |
{{: | {{: | ||
- | |||
- | ==== 6. Updating with latest rules ==== | ||
- | |||
- | If you have already installed suricata and you want to update with the latest rules. Use the following command. | ||
- | |||
- | < | ||
- | |||
- | |||
- | |||
- | |||
- | |||
tips/suricata-eve-unixsocket.txt · Last modified: 2020/09/28 17:22 by navaneeth