Suricata VARS #13332
-
Version2.4.80 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU16-32 RAM16-32 Storage for /200-300 GB Storage for /nsm1 TB Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusYes, there are salt failures (please provide detail below) LogsNo, there are no additional clues DetailHello! After upgrading to version 2.4.80, I noticed a problem with changing the EXTERNAL NET in web-interface configuration. After entering the parameter !$HOME_NET and synchronization via the cli command "salt sensor-*_sensor state.apply suricata" In the output to the suricata file.yaml was recorded only first symbol "!" Example:
After that, I compared the new sensor and the old one that was deployed on an earlier version and saw the difference in the files sensor-old: suricata: sensor-new: (not working conf) And this problem on all new added sensors when I try to chang EXTERNAL_NET via vars in web configuration Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 2 replies
-
What is the output of |
Beta Was this translation helpful? Give feedback.
This change coming in
2.4.90
should fix that issue. #13340EXTERNAL_NET: '!$HOME_NET'
that configuration should be: