Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- --- suricata_default.yaml 2018-05-20 11:34:57.618505320 -0600
- +++ suricata_modified.yaml 2018-05-20 11:35:11.274089496 -0600
- @@ -52,12 +52,12 @@
- default-rule-path: /etc/suricata/rules
- rule-files:
- - botcc.rules
- - # - botcc.portgrouped.rules
- + - botcc.portgrouped.rules
- - ciarmy.rules
- - compromised.rules
- - drop.rules
- - dshield.rules
- -# - emerging-activex.rules
- + - emerging-activex.rules
- - emerging-attack_response.rules
- - emerging-chat.rules
- - emerging-current_events.rules
- @@ -65,12 +65,12 @@
- - emerging-dos.rules
- - emerging-exploit.rules
- - emerging-ftp.rules
- -# - emerging-games.rules
- -# - emerging-icmp_info.rules
- -# - emerging-icmp.rules
- + - emerging-games.rules
- + - emerging-icmp_info.rules
- + - emerging-icmp.rules
- - emerging-imap.rules
- -# - emerging-inappropriate.rules
- -# - emerging-info.rules
- + - emerging-inappropriate.rules
- + - emerging-info.rules
- - emerging-malware.rules
- - emerging-misc.rules
- - emerging-mobile_malware.rules
- @@ -93,15 +93,15 @@
- - emerging-voip.rules
- - emerging-web_client.rules
- - emerging-web_server.rules
- -# - emerging-web_specific_apps.rules
- + - emerging-web_specific_apps.rules
- - emerging-worm.rules
- - tor.rules
- # - decoder-events.rules # available in suricata sources under rules dir
- # - stream-events.rules # available in suricata sources under rules dir
- - - http-events.rules # available in suricata sources under rules dir
- - - smtp-events.rules # available in suricata sources under rules dir
- - - dns-events.rules # available in suricata sources under rules dir
- - - tls-events.rules # available in suricata sources under rules dir
- +# - http-events.rules # available in suricata sources under rules dir
- +# - smtp-events.rules # available in suricata sources under rules dir
- +# - dns-events.rules # available in suricata sources under rules dir
- +# - tls-events.rules # available in suricata sources under rules dir
- # - modbus-events.rules # available in suricata sources under rules dir
- # - app-layer-events.rules # available in suricata sources under rules dir
- # - dnp3-events.rules # available in suricata sources under rules dir
- @@ -544,7 +544,7 @@
- # Linux high speed capture support
- af-packet:
- - - interface: eth0
- + - interface: eth1
- # Number of receive threads. "auto" uses the number of cores
- #threads: auto
- # Default clusterid. AF_PACKET will load balance packets based on flow.
- @@ -610,6 +610,7 @@
- # checksum off-loading is used.
- # Warning: 'checksum-validation' must be set to yes to have any validation
- #checksum-checks: kernel
- + checksum-checks: no
- # BPF filter to apply to this interface. The pcap filter syntax apply here.
- #bpf-filter: port 80 or udp
- # You can use the following variables to activate AF_PACKET tap or IPS mode.
- @@ -904,7 +905,7 @@
- # Note: parser depends on experimental Rust support
- # with --enable-rust-experimental passed to configure
- ntp:
- - enabled: no
- + enabled: yes
- # Limit for the maximum number of asn1 frames to decode (default 256)
- asn1-max-frames: 256
Advertisement
Add Comment
Please, Sign In to add comment