Suricata rules files specified but not loaded error #15454
-
Version2.4.201 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU12 RAM32 Storage for /200 Storage for /nsm400 Network Traffic Collectiontap Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusYes, there are salt failures (please provide detail below) LogsYes, there are additional clues in /opt/so/log/ (please provide detail below) DetailMy forward nodes are reporting they are unable to find a rules file in /etc/suricata/rules. This path doesn't exist on my nodes. but I do have rules files under /opt/so/conf/suricata/rules. I have recently run Soup and ran salt-call state.highstate on the forward nodes and on the manager but calling it doesn't create the path the config wants. The docker for Suricata only has PLACEHOLDER in the /etc/suricata/rules file path. Is there a config i should change, or is something misconfigured elsewhere? Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 9 replies
-
|
Looking at the fixes page, specifically #15396 , would I need to change my Suricata config to look for all.rules in /opt/so/conf, and would I need to change how my nodes are getting those rule files from updates? Also following along to #15429 |
Beta Was this translation helpful? Give feedback.


Well, turns out what I was missing was adding the proxy into each ruleset source. I used my http proxy in each rule, synced SOC, and ran a full update on Suricata. Still not sure if anything needs to be done with so-rule-update since idstools is gone now, but I'm getting Suricata logs now.