-
Version2.4.200 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU32 RAM128G Storage for /400GB Storage for /nsm3TB Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHi, Over the years I set up some custom Suricata rules basically pass-ing traffic that clearly are false positives. Today I needed to adapt one of these rules to cover additional source addresses by changing the rule from to At the same time I needed to extend old: new: i.e. three IPs added in YAML-syntax as usual. After clicking the green checkmark
the usual popup of
but once I clicked on "Synchronize Suricata"...
In order to strip down the problem I even tried removing all custom variables entirely just leaving an empty input window, but again
So even if there absolutely no variables are defined I get the same error. NB: Please note that the last change I did wrt. variables dates back to pre-2.4.200 - had no problems at all. Could it be that something has changed wrt. custom Suricata variables in 2.4.200? Thanks in advance for any clue. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 3 replies
-
|
Check the SOC log at For Suricata variables, you can set them in |
Beta Was this translation helpful? Give feedback.




It would be easier to manage in
SOC > Administration > Configuration > suricata > config > vars > address-groups. This would also be the preferred way.Putting the below in
suricata > advanced [adv]still works:My vars in the suricata.yaml shows it applied: