31
Intrusion Detection and Prevention / 21.7 adding custom rules to IDS doesn't seem to work
« on: July 31, 2021, 01:36:10 am »
I can't get my custom IDS rules to load. I've rebooted, waited a day, etc. Perhaps when using Proofpoint ET ruleset it won't add custom rules??
Here my file "spamhausBCL.xml" and it's placed in usr/local/opnsense/scripts/suricata/metadata/rules/spamhausBCL.xml
Any ideas?
Here my file "spamhausBCL.xml" and it's placed in usr/local/opnsense/scripts/suricata/metadata/rules/spamhausBCL.xml
Code: [Select]
<?xml version="1.0"?>
<ruleset>
<location url="https://pub-api.spamhaus.org/api/snort/" prefix="spamhausBCL"/>
<files>
<file url="https://pub-api.spamhaus.org/api/snort/?account=xxxxxxxxxxxxxxx&key=yyyyyyyyyyyyy"
description="Spamhaus Botnet Controller List"
documentation_url="https://www.spamhaus.org/bcl/"
>spamhausBCL.rules</file>
</files>
</ruleset>
Any ideas?