Skip to content
Discussion options

You must be logged in to vote

Just an update after spending hours messing with things. I found Wazuh rules stopped working after I cleared out the example rule in /nsm/wazuh/etc/rules/local_rules.xml. It appears the missing tag was required to remain otherwise Wazuh goes nuts. I found a sample of the original example rule and replaced it, and after restarting Wazuh it began producing alerts.

Thinking that one minor change is what caused that issue, I turned my attention to Suricata. The only change I made was to use the Talos ruleset, which I did during the install. So I changed the config in securityonion_standalone.sts to:

idstools:
  config:
    ruleset: 'ETOPEN'

Ran sudo salt securityonion_standalone state.apply …

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
1 reply
@netsecninja
Comment options

Comment options

You must be logged in to vote
0 replies
Answer selected by netsecninja
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants