Project

General

Profile

Actions

Feature #590

closed

document pulledpork for rule updates

Added by Victor Julien about 12 years ago. Updated about 6 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Target version:
Effort:
Difficulty:
Label:

Actions #1

Updated by Andreas Moe over 9 years ago

Thinking that maybe this falls abit outside the scope of the suricata docs? Using suricata will be the same regardless of what rulemanagement framework a person uses.

Actions #2

Updated by Victor Julien over 9 years ago

I think it's a critical step for most users to use a rule manager, with generally a few Suricata specific aspects. So it would make sense for us to document it, and also to recommend it to users.

Actions #3

Updated by Andreas Herz almost 9 years ago

  • Assignee set to Andreas Herz
Actions #4

Updated by Andreas Herz almost 9 years ago

Does anyone have a working pulledpork.conf for Suricata and ETOpen?

Actions #5

Updated by Andreas Herz almost 9 years ago

  • Assignee changed from Andreas Herz to Anonymous
Actions #6

Updated by Fanny Dwargee over 7 years ago

Hi,

there's just one thing that Pulledpork currently lacks for Suricata and that's the signal compatibility (Snort uses SIGHUP for reloading its rules and it's harcoded into the Pulledpork code).

That GitHub PR https://github.com/shirkdog/pulledpork/pull/274 provides full support for Suricata signal compatiblity but I'm afraid the Pulledpork guy it's a bit lazy accepting PR. :)

I myself use the current version of Pulledpork with the aforementioned patch and works like a charm, so, in the end the key points are just changing (apart from the common options for the rules) the pid_path and the snort version in the pulledpork.conf file this way:
pid_path=/usr/local/var/run/suricata.pid
snort_version=suricata-4.0

Hope that helps

Actions #7

Updated by Fanny Dwargee over 7 years ago

Forgot to mention how run Pulledpork with the above patch:

pulledpork.pl -H SIGUSR2 -c /usr/local/etc/pulledpork/pulledpork.conf -E -T

Actions #8

Updated by Jason Ish over 6 years ago

  • Effort set to low
  • Difficulty set to low

I'd like to suggest closing this ticket. I think it should be up to Pulled Pork to document using it for Suricata. I'd suggest the same for Oinkmaster, but for historical reasons maybe it should stay. However, once Suricata-Update is bundled, maybe we should remove Oinkmaster documentation as well.

Actions #9

Updated by Victor Julien about 6 years ago

  • Status changed from New to Closed
  • Effort deleted (low)
  • Difficulty deleted (low)
Actions

Also available in: Atom PDF