You can use YAML configuration files to define Default or Custom Sensor settings. This configuration manages how the Sensor interacts with various protocols and system resources.
Key configuration options
Packet capture: Enables the collection of network packets for forensic analysis.
Syslog settings: Configures the destination and format for system log alerts.
Protocol behavior: Defines how the engine parses and inspects specific network protocols.
How to import and export YAML files
Import YAML files
Prerequisites:
You must export the default YAML file to use as a template for creating and importing custom YAML files.
If the Suricata Sensor enters an operational state that is not ideal due to custom YAML misconfigurations, you can recover the Sensor by applying the default YAML configuration from the Manager. This action resets the Suricata Sensor YAML configurations to factory defaults.
Steps:
To export the file, do the following:
Go to Policy → <Admin Domain Name> → Intrusion Prevention → Suricata Configuration and click YAML Configuration tab. The YAML Configuration tab is displayed.
Next, go to Manage YAML File, select Export and choose Default YAML File. The existing YAML file will be downloaded.
The YAML file is the parent file and contains references to additional child .config files. To import a YAML file with its associated configuration files, select a .zip file. The system supports the following configuration files:
Classification.config
References.config
Threshold.config
Important
Use only the following names for configuration files:
classification.config,reference.config, andthreshold.config. If you specify any other name, the Manager displays an error.
Steps:
Go to Policy → <Admin Domain Name> → Intrusion Prevention → Suricata Configuration and click YAML Configuration tab. The YAML Configuration tab is displayed.
Select Custom from YAML File in YAML Configuration page.
Select Import from Manage YAML File drop-down. The Import YAML File window is displayed.
Important
The Manager only supports files with the
.yamland.zipextensions.Click on Browse and select the required YAML file. Next, click Import.
The File Import Complete message displays after a successful import.
The Manager will store the .yaml and .config file content inside iv_suricata_yaml_files table.
Export YAML files
Steps:
Go to Policy → <Admin Domain Name> → Intrusion Prevention → Suricata Configuration and click YAML Configuration tab. The YAML Configuration tab is displayed.
Next, go to Manage YAML File and select Export. Choose Default YAML File or Custom YAML File based on your requirement.
The selected YAML file will be downloaded.