-
Hello, I use Security onion in distributed architecture. Let me explain:
I create the alerts via the GUI in the “Detection” tab, then perform a “differentiale update” to synchronize the rules. What am I doing wrong? I don't understand this behavior and it's hell to test and debug custom rules. Thanks in advance for all your answers! |
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 1 reply
-
What version of Security Onion are you running? |
Beta Was this translation helpful? Give feedback.
-
Hello, I'm on version 2.4.110 in distributed deployment. I solved the rule duplication problem with the same ID by manually deleting one of the 2 rules in the “/opt/so/rules/nids/suri/local.rules” file. It seems that this deletion via the GUI was not possible and required a manual deletion directly in the file. |
Beta Was this translation helpful? Give feedback.
-
I just tested on 2.4.110 as follows and deletion via GUI works for me:
Please try this and see if it works for you. From https://docs.securityonion.net/en/2.4/detections.html#ruleset-changes: |
Beta Was this translation helpful? Give feedback.
I just tested on 2.4.110 as follows and deletion via GUI works for me:
Please try this and see if it works for you.
From https://docs.securityonion.net/en/2.4/detections.html#ruleset-changes: