Project

General

Profile

Actions

Feature #3697

open

a command line option for suricata-update that would set downloaded rules to their default state

Added by Risto Vaarandi almost 4 years ago. Updated over 2 years ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
-
Effort:
Difficulty:
Label:

Description

When downloading and activating rules, suricata-update applies disable and enable filters for rules, but apparently there is no way to disable the rule if it has been disabled in the original downloaded rule file. However, if the rule has been commented out in the original rule file, it often indicates the fact it is regarded prone to false positives by its authors.

PulledPork addresses this issue nicely and supports -R command line option for that purpose, and this option is very handy for disabling noisy rules (see https://github.com/shirkdog/pulledpork for more details).

Would it be possible to introduce a similar command line option (or configuration file setting) for suricata-update?

Actions

Also available in: Atom PDF