Updating IDS rules
Details about updating IDS rules.
Product: Flowmon IDS Probe
Is the Suricata properly reloaded when restarting the "flowmon-idsp-suricata-update" service?
|Steps to Reproduce:|
Custom rules can be added directly to the /data/idsp/user-config/rules directory. The configuration will be applied during the next execution of the Suricata-Update tool. The tool is scheduled to be executed every hour.
It is also possible to apply the configuration immediately by restarting the service via the:
sudo systemctl restart flowmon-idsp-suricata-update
When the service is restarted, the Suricata rules are generated to /data/idsp/rules and Suricata is reloaded via
kill -USR2 $(pidof suricata)