Security-Onion-Solutions / security-onion

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management
https://securityonion.net
3.06k stars 521 forks source link

Suricata 5.0.5 #1651

Closed dougburks closed 3 years ago

dougburks commented 4 years ago

https://suricata-ids.org/2019/10/15/release-notes-for-5-0-0/

dougburks commented 4 years ago

https://suricata-ids.org/2019/12/13/suricata-5-0-1-released/

haricsree commented 4 years ago

Just curious why Suricata 5.0.x is not yet in included? Suricata 5.0.2 is released in Feb. https://suricata-ids.org/2020/02/13/suricata-5-0-2-released/

dougburks commented 4 years ago

Hi @haricsree ,

First, please note that there is no rush in moving to Suricata 5.0.x since Suricata 4.1.x is still fully supported through the end of 2020: https://suricata-ids.org/2020/03/25/suricata-4-1-eol-update-support-extended/

Second, please note that there is currently a stability issue with Suricata 5.0.x: https://redmine.openinfosecfoundation.org/issues/3342?issue_count=191&issue_position=1&next_issue_id=3341

haricsree commented 4 years ago

Thanks for the explanation. Did not realize that there is an outstanding issue with Suricata 5.0.x

NRGLine4Sec commented 4 years ago

Hi @dougburks It seems to be claused https://redmine.openinfosecfoundation.org/issues/3342?issue_count=191&issue_position=1&next_issue_id=3341#note-14

dougburks commented 4 years ago

We are moving to Suricata 5 in our new Hybrid Hunter platform: https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/418

Our existing 16.04 platform will likely remain on Suricata 4 at least for the near future.

NRGLine4Sec commented 4 years ago

Hi @dougburks Does this imply that Hybrid Hunter will soon become a production version ?

dougburks commented 4 years ago

Depends on your definition of "soon". Hybrid Hunter is currently at Beta 2 release. We're not promising any dates for final release at this point.

dougburks commented 3 years ago

Security Onion 2 has been released and includes Suricata 5: https://blog.securityonion.net/2020/10/security-onion-2-has-reached-general.html

For Security Onion 16.04, we need to move to Suricata 5 before Suricata 4.1 reaches EOL on 12/31/2020: https://suricata-ids.org/2020/10/08/suricata-4-1-9-and-5-0-4-released/

dougburks commented 3 years ago

Suricata 5.0.5 has been released: https://suricata-ids.org/2020/12/04/suricata-6-0-1-5-0-5-and-4-1-10-released/

https://www.openinfosecfoundation.org/download/suricata-5.0.5.tar.gz

dougburks commented 3 years ago

I've packaged Suricata 5.0.5 and the following package is now available at ppa:securityonion/test:

securityonion-suricata - 5.0.5-1ubuntu1securityonion2

Please test/verify as follows:

Thanks in advance for your time and effort!

cm-ops commented 3 years ago

Testing guidelines were verified as follows: suricata.yaml backed up, HOME_NET and EXTERNAL_NET variables migrated, notification to run sudo rule-update, and to update suricata.yaml with customizations. Also, new version number seen on each test.

dougburks commented 3 years ago

Thanks @cm-ops !

dougburks commented 3 years ago

Published: https://blog.securityonion.net/2020/12/suricata-505-now-available-for-security.html