Skip to content
Discussion options

You must be logged in to vote

We have a new tool that was released with 2.3.21 that might be of help - so-suricata-testrule $RuleFile $FullPathToPCAP

Point it to your custom rule and a pcap (full path) and it will run run Suricata with that custom rule + all.rules against the target PCAP. Make sure to run it on a node that has the sensor role:

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@mmasino-matc
Comment options

Answer selected by defensivedepth
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants