Rulesets are files that determine how the Sensor handles network traffic.
Tip
Administrators can provide custom rule files based on specific organizational security requirements.
You can manage the rulesets for Suricata Sensor in Ruleset tab. Go to Policy → <Admin Domain Name> → Intrusion Prevention → Suricata Configuration and click Ruleset tab. The Ruleset tab is displayed.
The following ruleset file details are displayed:
Option | Definition |
|---|---|
Ruleset Name | Name of the ruleset file. |
Publisher Name | Name of the publisher of the ruleset file. |
Ruleset File | Ruleset file name. |
Ruleset Version | Version of ruleset file. |
Imported By | Details of the ruleset file importer. |
Imported Date | Last imported date in DD-MMM-YYYY format. |
How to import, export, and delete ruleset files
You can import the suricata rules file from your Threat Content Provider into the IPS Manager, then deploy the file to the IPS Sensor.
Import ruleset files
Steps:
Go to Policy → <Admin Domain Name> → Intrusion Prevention → Suricata Configuration and click Ruleset tab. The Ruleset tab is displayed.
Select Import from Manage Ruleset drop-down. The Import or Update Suricata Ruleset is displayed.
Important
The Manager only supports files with the
.rulesextension.Suricata Ruleset File: Click Browse and select the required ruleset file.
Ruleset Name: Displays the name of the ruleset file.
Publisher Name: Displays the publisher name.
Click Import.
The File Import Complete message displays after a successful import.
Export ruleset files
Steps:
Go to Policy → <Admin Domain Name> → Intrusion Prevention → Suricata Configuration and click Ruleset tab. The Ruleset tab is displayed.
Select Export from Manage Ruleset drop-down. The existing ruleset file will be downloaded.
Delete ruleset files
Steps:
Go to Policy → <Admin Domain Name> → Intrusion Prevention → Suricata Configuration and click Ruleset tab. The Ruleset tab is displayed.
Select Delete from Manage Ruleset drop-down. A Warning window is displayed.
Click Ok to delete the file.