Open woundride opened 1 year ago
Thank you for posting the report. I could not reproduce the issue. It is possible that it can take a bit of time for the ruelset reload to complete. What happens is , we start a ruelset reload via suricata native unix socket command and then it is triggered and goes through a regular reloading process.
But can you tail the actual suricata log and see if the update is going through:
tail -F containers-data/suricata/logs/suricata.log
and then do the update rulesets (select all actions please- fetch,build, push).
Thanks for your reply @pevma
Update is OK, I've verified in scirius.rules file in the container and my new rules have been added :
But, the file is not updated in conainers-data directory, strange 🤔 :
When I try tail -f on containers-data/suricata/logs/suricata.log, no news logs :
News logs appear only when I restart Suricata container :
But files in /opt/selksd/SELKS/docker/containers-data/suricata/etc/rules are always not updated.
Please see https://github.com/StamusNetworks/scirius/issues/290 for proper setup
I've updated Scirius container on 2023/07/24
From update, when I build & push ruleset, Suricata won't restart :
To mitigate and apply ruleset immediately, I restart container :
selks-user@selks:~$ sudo docker restart suricata