Skip to content
Discussion options

You must be logged in to vote

Found my solution to my issue by messing around in the scripts. I noticed that in /usr/sbin/so-rule-update it has this portion to download from the internet.

However when I check /opt/so/saltstack/default/salt/idstools/tools/sbin_jinja/so-rule-update I see this check that technically true but it still runs and downloads from the internet. I'm not an expert so I could be looking at something completely incorrect so apologies.

I'm aware that salt will automatically pull the rules from /nsm/rules/suricata/emerging-all.rules down to the sensors also. I was just curious why all of a sudden this had changed whether it was done purposefully or not.
I found that running this command will pull f…

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
2 replies
@Maji-Shan
Comment options

@reyesj2
Comment options

Comment options

You must be logged in to vote
0 replies
Answer selected by Maji-Shan
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
3 participants