-
Hi, I have installed Securityonion 2.3.5 recently with Snort Subscriber Ruleset. The setup works fine, but I also want to enable ET OPEN rulesets along with the current Snort rulesets. Can someone let me know how to enable them as I have gone through the documentation but could not understand how to enable them? Previously, in Securityonon 16, both rulesets were selected in the initial setup. For this version, please let me know how to do it, many thanks. |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 7 replies
-
Have you reviewed the Rules section of the documentation? |
Beta Was this translation helpful? Give feedback.
Looking at your manager.sls screenshot, have you tried having a single
config
section underidstools
that contains your TALOS ruleset and oinkcode and then specifies the ET URL underurls
as shown at https://docs.securityonion.net/en/2.3/rules.html#other?