Skip to content
Discussion options

You must be logged in to vote

The suricata.yaml file is located at /opt/so/conf/suricata/suricata.yaml

But that is not where you will edit the yaml.
You need to edit the file in the global.sls or minions depending on exactly what you are trying to change.

Link to the docs reference: https://docs.securityonion.net/en/2.3/suricata.html?highlight=suricata.yaml#configuration

Configuration
You can configure Suricata’s suricata.yaml using Salt. The defaults for this have been defined in https://github.com/Security-Onion-Solutions/securityonion/blob/master/salt/suricata/defaults.yaml. Under suricata:config, the pillar structure follows the same YAML structure of the suricata.yaml file.

For example, suppose you want to change…

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Answer selected by Blason
Comment options

You must be logged in to vote
1 reply
@xfaith
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants