OPNsense 19.1.b_306-amd64FreeBSD 11.2-RELEASE-p4-HBSDOpenSSL 1.0.2q 20 Nov 2018
abuse.ch/Dyre SSL IPBL not installed drop abuse.ch/Feodo Tracker 2018/12/01 1:31 drop abuse.ch/SSL Fingerprint Blacklist not installed drop abuse.ch/SSL IP Blacklist not installed drop
Dec 1 01:30:43 suricata: [100244] <Notice> -- Stats for 'em1': pkts: 283, drop: 0 (0.00%), invalid chksum: 0
ec 1 01:30:23 suricata: [100172] <Error> -- [ERRCODE: SC_ERR_INVALID_YAML_CONF_ENTRY(139)] - Invalid mpm algo supplied in the yaml conf file: "hs"
I was going through old threads and saw that, went to their site and no mention of continuing problems. I'll turn off the 4 and try your suggestion which ET rules would you recommend?thank you
...I went to download the eicar test and it let me know it was a virus so that works but I don't see any blocked in the alerts. I used this site ( http://www.wicar.org/test-malware.html ) and it also blocked the flash and java script by only opening completly blank pages. I use firefox and run opensuse tumbleweed.I probably should also mention I'm only using the WAN and not the lan if it makes any difference?
clog -f /var/log/suricata.logtail -f /var/log/suricata/stats.log
...All of them? I only did 5 to see how it works and so far I have yet to have anything show up in alerts. CPU usuage is still minimal, memory usage did go up and the load avg went up very slightly so I think I'll load a few at a time and go from that.
Ah ha, I have things set to drop. So you need something set to alert for it to show in the gui?So the alerts tab is more for testing to see what rules are messing up and son't really need to be dropped?
Yes I found the second place to either drop or alert the rules. There's over 16,000!How in the heck do you enable them all ? There has to be a quick way to do so with out scrolling through them all I hope.And I still didn't download/enable all the ET rules hmmmmm
Doh
Dec 1 11:27:33 suricata[66339]: [100275] <Notice> -- all 2 packet processing threads, 4 management threads initialized, engine started.Dec 1 11:27:28 suricata[66339]: [100275] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.armwget' is checked but not set. Checked in 2024241 and 1 other sigsDec 1 11:27:28 suricata[66339]: [100275] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'min.gethttp' is checked but not set. Checked in 2023711 and 0 other sigsDec 1 11:27:28 suricata[66339]: [100275] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.autoit.ua' is checked but not set. Checked in 2019165 and 0 other sigsDec 1 11:27:28 suricata[66339]: [100275] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'et.MCOFF' is checked but not set. Checked in 2022303 and 0 other sigsDec 1 11:27:28 suricata[66339]: [100275] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ETPRO.RTF' is checked but not set. Checked in 2020700 and 0 other sigsDec 1 11:27:28 suricata[66339]: [100275] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.MSSQL' is checked but not set. Checked in 2020569 and 0 other sigsDec 1 11:27:28 suricata[66339]: [100275] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'et.DocVBAProject' is checked but not set. Checked in 2020170 and 0 other sigsDec 1 11:27:28 suricata[66339]: [100275] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.ELFDownload' is checked but not set. Checked in 2019896 and 0 other sigsDec 1 11:27:28 suricata[66339]: [100275] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'etpro.clsid.detected' is checked but not set. Checked in 2002172 and 0 other sigsDec 1 11:27:28 suricata[66339]: [100275] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'et.MS.WinHttpRequest.no.exe.request' is checked but not set. Checked in 2022653 and 0 other sigs