Suricata Installation: Unterschied zwischen den Versionen

Aus Xinux Wiki
Zur Navigation springen Zur Suche springen
Markierung: Ersetzt
 
(3 dazwischenliegende Versionen von 2 Benutzern werden nicht angezeigt)
Zeile 6: Zeile 6:
 
  This is Suricata version 6.0.1 RELEASE
 
  This is Suricata version 6.0.1 RELEASE
  
 +
<!--
 
=Update Rules=
 
=Update Rules=
  
 
* suricata-update
 
* suricata-update
 
+
-->
=Suricata minimale Konfiguration=
 
 
 
* '''vim /etc/suricata/suricata.yaml'''
 
<pre>
 
%YAML 1.1
 
---
 
# Variablen für die Adressgruppen festlegen
 
vars:
 
  address-groups:
 
    LAN: "[192.168.10.0/24]"
 
    DMZ: "[172.18.10.0/24]"
 
    INT: "[$LAN,$DMZ]"
 
    EXTERNAL_NET: "!$INT"
 
 
 
# Standard-Log-Verzeichnis
 
default-log-dir: /var/log/suricata/
 
 
 
# Statistiken aktivieren
 
stats:
 
  enabled: yes
 
  interval: 8
 
 
 
# Ausgaben konfigurieren
 
outputs:
 
  - fast:
 
      enabled: yes
 
      filename: fast.log
 
      append: yes
 
  - alert-debug:
 
      enabled: yes
 
      filename: alert-debug.log
 
      append: yes
 
  - stats:
 
      enabled: yes
 
      filename: stats.log
 
      append: yes
 
      totals: yes
 
      threads: no
 
 
 
# Logging-Einstellungen
 
logging:
 
  default-log-level: notice
 
  outputs:
 
  - console:
 
      enabled: yes
 
  - file:
 
      enabled: yes
 
      level: info
 
      filename: suricata.log
 
 
 
# Netzwerkschnittstellen konfigurieren
 
af-packet:
 
  - interface: enp0s3
 
    threads: auto
 
    cluster-id: 97
 
    cluster-type: cluster_flow
 
    defrag: yes
 
  - interface: enp0s8
 
    threads: auto
 
    cluster-id: 98
 
    cluster-type: cluster_flow
 
    defrag: yes
 
  - interface: enp0s9
 
    threads: auto
 
    cluster-id: 99
 
    cluster-type: cluster_flow
 
    defrag: yes
 
 
 
# PID-Datei
 
pid-file: /var/run/suricata.pid
 
 
 
# Coredump-Einstellungen
 
coredump:
 
  max-dump: unlimited
 
 
 
# Host-Modus
 
host-mode: auto
 
 
 
# Unix-Befehlseingabe konfigurieren
 
unix-command:
 
  enabled: yes
 
  filename: /var/run/suricata-command.socket
 
 
 
# Engine-Analyse-Einstellungen
 
engine-analysis:
 
  rules-fast-pattern: yes
 
  rules: yes
 
 
 
# Defragmentierungseinstellungen
 
defrag:
 
  memcap: 32mb
 
  hash-size: 65536
 
  trackers: 65535
 
  max-frags: 65535
 
  prealloc: yes
 
  timeout: 60
 
 
 
# Standardregelverzeichnis
 
default-rule-path: /etc/suricata/rules
 
 
 
# Regel-Dateien
 
rule-files:
 
  - local.rules
 
 
 
# Klassifikationsdatei
 
classification-file: /etc/suricata/classification.config
 
 
 
# Referenzkonfigurationsdatei
 
reference-config-file: /etc/suricata/reference.config
 
 
 
nfq:
 
  mode: repeat
 
  repeat-mark: 1
 
  repeat-mask: 1
 
                         
 
 
 
 
 
</pre>
 

Aktuelle Version vom 24. April 2025, 15:40 Uhr

Installation

  • sudo apt update
  • sudo apt -y install suricata
  • systemctl stop suricata
  • suricata -V
This is Suricata version 6.0.1 RELEASE