241
Intrusion Detection and Prevention / Re: ET telemetry rules - no auto updates
« on: May 31, 2020, 07:36:58 pm »
When we entered Services -> Intrusion Detection -> Log File we see this:
2020-05-22T11:10:12 suricata: [100585] <Notice> -- rule reload complete
2020-05-22T11:06:13 suricata: [100585] <Notice> -- rule reload starting
2020-05-21T11:10:21 suricata: [100585] <Notice> -- rule reload complete
2020-05-21T11:06:20 suricata: [100585] <Notice> -- rule reload starting
This means that the rules have been reset, but sometimes new rules will have been downloaded and sometimes not. To know when new rules have been downloaded, you must enter the Opnsense Dashboard and enable the Proofpoint widget (Telemetry status)
2020-05-22T11:10:12 suricata: [100585] <Notice> -- rule reload complete
2020-05-22T11:06:13 suricata: [100585] <Notice> -- rule reload starting
2020-05-21T11:10:21 suricata: [100585] <Notice> -- rule reload complete
2020-05-21T11:06:20 suricata: [100585] <Notice> -- rule reload starting
This means that the rules have been reset, but sometimes new rules will have been downloaded and sometimes not. To know when new rules have been downloaded, you must enter the Opnsense Dashboard and enable the Proofpoint widget (Telemetry status)