Actions
Bug #2688
closed
KK
SB
filemd5 files are not migrated /w rules
Bug #2688:
filemd5 files are not migrated /w rules
Affected Versions:
Effort:
Difficulty:
Label:
Description
When rules using a filemd5 directive are imported the rules are migrated to /var/lib/suricata/rules/suricata.rules, but the related files are left in their original location (likely /etc/suricata/rules), which breaks the references.
alert http any any -> $HOME_NET any (msg:"OTX - FILE MD5 from pulse Threats Targeted against Civil Society"; filemd5:5bedad78bb5ab60a53de19a4.txt; reference: url, otx.alienvault.com/pulse/5bedad78bb5ab60a53de19a4; sid:411683; rev:1;)
Referenced files should be migrated along with their related rules.
To work around this I currently run the following command prior to Suricata-Update to generate hard links on relevant files between the two locations:
sudo cp -l /etc/suricata/rules/???????????*.txt /var/lib/suricata/rules
Files
Actions