Skip to content

Frustrated with BPF and NIDS Rules #1931

Locked Answered by TOoSmOotH
WPTechnician asked this question in General
Discussion options

You must be logged in to vote

This all belongs in the minion pillar not global. The minion config will overwrite the global. See https://docs.securityonion.net/en/2.3/managing-alerts.html?highlight=minionid where it details this. Once you change that run so-idstools-restart.

Next look to see if the rules are disabled:
cat /opt/so/rules/nids/all.rules | grep 2100366 and make sure it is disabled.

If the rules are commented out then they are disabled. You would then need to restart suricata or wait for them to check in to restart themselves. The old alerts will still show up only new alerts will stop.

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
0 replies
Answer selected by TOoSmOotH
Comment options

You must be logged in to vote
2 replies
@WPTechnician
Comment options

@TOoSmOotH
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants