Not sure if this is the appropriate forum for this, so please feel free to redirect me.
I'm trying to run PCAP through the docker image for SELKS, but the suricata.yaml file shows regular suricata settings...
Is there a way to reference the docker image to run suricata... In other words, If I run amsterdam -d ams start it will start suricata just fine, but I want to run PCAP through the docker suricata. What is the best way to do this?
Not sure if this is the appropriate forum for this, so please feel free to redirect me.
I'm trying to run PCAP through the docker image for SELKS, but the suricata.yaml file shows regular suricata settings...
Is there a way to reference the docker image to run suricata... In other words, If I run amsterdam -d ams start it will start suricata just fine, but I want to run PCAP through the docker suricata. What is the best way to do this?