suricata: Rule files are now located in /var/lib/suricata

Place the rulefiles from now in "/var/lib/suricata".

Fixes #11834

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
This commit is contained in:
Stefan Schantl
2018-08-29 12:34:08 +02:00
parent d2e6bf6e5f
commit 21cab141ec
5 changed files with 20 additions and 12 deletions

View File

@@ -35,7 +35,7 @@ our $rulestarball = "/var/tmp/idsrules.tar.gz";
our $storederrorfile = "/tmp/ids_storederror";
# Location where the rulefiles are stored.
our $rulespath = "/etc/suricata/rules";
our $rulespath = "/var/lib/suricata";
# File which contains a list of all supported ruleset sources.
# (Sourcefire, Emergingthreads, etc..)

View File

@@ -1,8 +1,4 @@
etc/suricata
#etc/suricata/rules
etc/suricata/rules/classification.config
etc/suricata/rules/reference.config
etc/suricata/rules/threshold.config
etc/suricata/suricata.yaml
usr/bin/suricata
#usr/bin/suricatasc
@@ -43,6 +39,10 @@ usr/bin/suricata
#usr/share/doc/suricata/Ubuntu_Installation_from_GIT.txt
#usr/share/doc/suricata/Windows.txt
#usr/share/man/man1/suricata.1
#var/lib/suricata
var/lib/suricata/classification.config
var/lib/suricata/reference.config
var/lib/suricata/threshold.config
var/log/suricata
#var/log/suricata/certs
#var/log/suricata/files

View File

@@ -40,14 +40,14 @@ vars:
##
## Ruleset specific options.
##
default-rule-path: /etc/suricata/rules
default-rule-path: /var/lib/suricata
rule-files:
# Include enabled ruleset files from external file.
include: /var/ipfire/suricata/suricata-used-rulefiles.yaml
classification-file: /etc/suricata/rules/classification.config
reference-config-file: /etc/suricata/rules/reference.config
# threshold-file: /etc/suricata/threshold.config
classification-file: /var/lib/suricata/classification.config
reference-config-file: /var/lib/suricata/reference.config
# threshold-file: /var/lib/suricata/threshold.config
##