brimdata / build-suricata

Build Suricata for packaging with Brim
8 stars 2 forks source link

how to add this to Brim MacOS version ? #68

Closed mostafazaghlol closed 4 months ago

philrz commented 1 year ago

@mostafazaghlol: Could you provide some more detail on what you're trying to achieve?

The Suricata artifact that comes out of this build repo is already part of Brim for macOS. The way it comes together is that Suricata (and Zeek) are included as analyzers in the Brimcap tool, and Brimcap is then bundled as part of Brim.

If you were asking because you want to do some kind of customization to the Suricata that runs with Brim, I'd not recommend working off this repo. There's a Custom Brimcap Configuration article in the Brimcap wiki that shows how to invoke analyzers other than the ones that come bundled with the app. That would allow you to use any Suricata that runs on macOS, such as the one available via Homebrew. That article happens to use Linux as a reference point, but completing the equivalent steps on macOS should be very similar and if you have any trouble I'd be happy to field your questions here or on our public Slack.

I'll hold this issue open to see if you're able to provide more detail on your intentions

philrz commented 4 months ago

@mostafazaghlol: Since we've not heard from you since this issue was first opened back in 2022 I'm going to assume the last comment either answered your question or you've moved on to something else, so I'm going to go ahead and close this. Feel free to comment again or come talk to us on our public Slack if you'd like to revisit the topic.