Skip to content
Discussion options

You must be logged in to vote

It would be easier to manage in SOC > Administration > Configuration > suricata > config > vars > address-groups. This would also be the preferred way.

Putting the below in suricata > advanced [adv] still works:

suricata:
  config:
    vars:
      address-groups: 
       JUPITER_NODE_ADDRESSES:
          - 192.168.2.1
          - 192.168.2.253
          - 192.168.2.254
          - 192.168.11.20
          - 192.168.11.21
          - 192.168.11.22
          - 192.168.21.1

My vars in the suricata.yaml shows it applied:

    vars:
      address-groups:
        HOME_NET: '[192.168.0.0/16,10.0.0.0/8,172.16.0.0/12]'
        EXTERNAL_NET: '[any]'
        HTTP_SERVERS: '[$HOME_NET]'
        SMTP_S…

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@ejgh-oe
Comment options

@cm-ops
Comment options

Answer selected by ejgh-oe
@ejgh-oe
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants