Suricata rule modification in SOC GUI #14948
-
Version2.4.170 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU12 RAM32 Storage for /500Gb Storage for /nsm16Tb Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHi! PS: of course, I can modify source of this rule in all.rules file. But next Suricata rule update will overwright my modifications, so I believe right way to do this - is throug using SOC GUI.... Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 3 replies
-
Beta Was this translation helpful? Give feedback.
Depending on how/where you want to put the value you could do something like below.
This yields a rule that looks like this: