Security-Onion-Solutions / security-onion

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management
https://securityonion.net
3.06k stars 517 forks source link

Suricata 4.1.9 #1788

Closed dougburks closed 3 years ago

dougburks commented 3 years ago

https://redmine.openinfosecfoundation.org/versions/148

Also enable the following in suricata.yaml by default (see https://suricata.readthedocs.io/en/latest/performance/tuning-considerations.html#af-packet):

   use-mmap: yes
   tpacket-v3: yes
dougburks commented 3 years ago

https://suricata-ids.org/2020/10/08/suricata-4-1-9-and-5-0-4-released/

dougburks commented 3 years ago

I've packaged Suricata 4.1.9 and the following package is now available at ppa:securityonion/test:

securityonion-suricata - 4.1.9-1ubuntu1securityonion1

Please test/verify as follows:

Thanks in advance for your time and effort!

cm-ops commented 3 years ago

Testing guidelines were verified as follows: suricata.yaml backed up (single and multiple interfaces), HOME_NET and EXTERNAL_NET variables migrated (single and multiple interfaces), notification to run sudo rule-update was seen on each interface, new version number seen on each test.

sudo rule-update: no issues PF_RING vs AF_PACKET: no issues Single worker vs multiple workers: no issues sostat: no issues Log files: no issues Reboot: no issues Re-run setup: no issues

dougburks commented 3 years ago

Thanks @cm-ops !

dougburks commented 3 years ago

Published: https://blog.securityonion.net/2020/10/suricata-419-now-available-for-security.html