Security-Onion-Solutions / security-onion

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management
https://securityonion.net
3.07k stars 522 forks source link

Snort 2.9.16.1 #1780

Closed dougburks closed 4 years ago

dougburks commented 4 years ago

https://blog.snort.org/2020/08/snort-29161-has-been-released.html

dougburks commented 4 years ago

I've packaged Snort 2.9.16.1 and the following package is now available at ppa:securityonion/test:

securityonion-snort - 2.9.16.1-1ubuntu1securityonion1

Please test as follows:

Thanks in advance for your time and effort!

cm-ops commented 4 years ago

Testing results: • Snort package should back up your existing snort.conf, migrate your HOME_NET and EXTERNAL_NET variables, and tell you that you need to run sudo rule-update o Checks okay – no issues

• Verify that your snort.conf has been updated and shows: VERSIONS: 2.9.16.1 o Checks okay – no issues

• Verify the new Snort version number o Checks okay – no issues

• Update your rules using PulledPork / Verify that PulledPork downloaded rules properly o Checks okay – no issues

• Verify that Snort is generating alerts properly in Sguil, Squert, and Kibana o Sguil, Squert, and Kibana check okay – no issues

• Increase Snort instances: • Verify that Snort is generating alerts and load-balancing traffic via PF_RING o Checks okay – no issues

• Check sostat output for anything out of the ordinary (specifically, check the pf_ring and Snort sections for packet loss) o No issues noted in sostat

• Reboot and make sure everything is still working properly o Checks okay – no issues

• Re-run Setup and verify that Snort and PulledPork work properly on new installations o Checks okay – no issues

• Check log files for errors or anything else out of the ordinary o Checks okay – no issues found in log files

• Verify no regressions o Checks okay – no issues.

dougburks commented 4 years ago

Thanks @cm-ops !

Published: https://blog.securityonion.net/2020/08/snort-29161-now-available-for-security.html