tips:suricata-eve-unixsocket
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| tips:suricata-eve-unixsocket [2020/09/10 16:28] – [2. Installing Suricata version 5.0] veera | tips:suricata-eve-unixsocket [2020/09/28 17:22] (current) – navaneeth | ||
|---|---|---|---|
| Line 22: | Line 22: | ||
| - | ===== Updating with latest ruleset | + | ==== 3. Updating with latest ruleset ==== |
| Use the following command to update the latest emerging-threats ruleset | Use the following command to update the latest emerging-threats ruleset | ||
| Line 32: | Line 32: | ||
| < | < | ||
| - | |||
| - | |||
| - | |||
| - | |||
| - | |||
| - | |||
| - | ==== 3. Installing Emerging Threat Rules 5.0 ==== | ||
| - | |||
| - | |||
| - | * You have to install the Emerging Threats Community which are a set of rules that trisul will listen to. | ||
| - | * Download and install Emerging Threats Open rules into /// | ||
| - | |||
| - | < | ||
| - | #wget https:// | ||
| - | #tar xf emerging.rules.tar.gz | ||
| - | </ | ||
| - | |||
| - | <note important> | ||
| ==== 4. Enabling EVE_unix Socket ==== | ==== 4. Enabling EVE_unix Socket ==== | ||
| Line 81: | Line 63: | ||
| {{: | {{: | ||
| + | |||
| + | ==== 7. Starting Suricata Automatically ==== | ||
| + | |||
| + | * You need to install [[monit: | ||
| + | |||
| + | * Add a shellscript named // | ||
| + | |||
| + | < | ||
| + | #!/bin/bash | ||
| + | |||
| + | echo " | ||
| + | /bin/rm -f / | ||
| + | |||
| + | echo " | ||
| + | / | ||
| + | |||
| + | echo "Done starting suricata"</ | ||
| + | |||
| + | * Make sure the shell script // | ||
| + | < | ||
| + | |||
| + | * You need to add the following statements in the /// | ||
| + | < | ||
| + | start program = "/ | ||
| + | </ | ||
| + | |||
| + | * Please ensure you restart monit | ||
| + | < | ||
| + | |||
| + | |||
| + | |||
| + | |||
| + | |||
tips/suricata-eve-unixsocket.1599735524.txt.gz · Last modified: 2020/09/10 16:28 by veera