Use the commands in this procedure to enable or disable custom YARA rules on your Network Security appliance. You cannot use the Web UI to configure YARA rules.
Note
You cannot configure YARA rules using the sensor CLI.
Prerequisites
An established connection between the Network Security appliance and the Internet.
Administrator or Operator access to the Network Security appliance.
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Enable the custom YARA rules.
hostname (config) # yara policy cust
Verify your configuration.
hostname (config) # show static-analysis config ..... Yara Configuration Yara policy : cust .....
Save your changes.
hostname (config) # write memory
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Disable the custom YARA rules.
hostname (config) # yara policy disable
Verify your configuration.
hostname (config) # show static-analysis config ..... Yara Configuration Yara policy : disable
Save your changes.
hostname (config) # write memory