Project

General

Profile

Actions

Support #3499

closed

Configuring rules for IDS/IPS

Added by Little Yu over 4 years ago. Updated over 4 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Affected Versions:
Label:

Description

Hello,

so I'm trying to use Suricata as an IDS/IPS but do not know if I should disable all rules and create custom rules but if so, how do I do it?

thank you

Actions #1

Updated by Victor Julien over 4 years ago

  • Tracker changed from Task to Support
  • Priority changed from High to Normal
Actions #2

Updated by Andreas Herz over 4 years ago

You can use suricata-update to manage rulesets. What you want to enable or disable depends on what you want to achieve. See https://suricata.readthedocs.io/en/latest/rule-management/index.html for more details about suricata-update.

Actions #3

Updated by Victor Julien over 4 years ago

  • Status changed from New to Closed
Actions

Also available in: Atom PDF