Skip to content

Can't activate custom rules #13988

Closed Answered by Cantondy
Cantondy asked this question in Q&A
Nov 28, 2024 · 2 comments · 1 reply
Discussion options

You must be logged in to vote

Hello,

thank you for your reply

After several tests, here's the procedure I use to check that a custom rule is active on forward nodes:

  1. Create the custom rule via the “Detection” tab
  2. On the manager node, do a so-rule-update and check that the rule is up to date in "/opt/so/rules/nids/suri/local.rules" (it may take ~5-8 minutes for the rule to be updated on the manager).
  3. Once the rule is up to date on the manager, issue the sudo so-suricata-restart command on the forward nodes and check that the rules are up to date in “opt/so/conf/suricata/rules/local.rules” (the rule update is almost instantaneous after the “so-suricata-restart” command).

Thanks for your answers!

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
1 reply
@techno-cat-1976
Comment options

Comment options

You must be logged in to vote
0 replies
Answer selected by Cantondy
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants