Local YARA rules #6556
-
Hi, Been looking to add some custom YARA rules and have been following the docs https://docs.securityonion.net/en/2.3/local-rules.html?#id1 however I'm a little confused. we run SO in a distributed deployment and the manager doesn't run strelka but does run on the sensor, the paths however ( |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
Hi @Trash-P4nda , I've just updated the documentation to be clearer. After adding your rules, update the configuration by running Alternatively, run |
Beta Was this translation helpful? Give feedback.
Hi @Trash-P4nda ,
I've just updated the documentation to be clearer.
After adding your rules, update the configuration by running
so-strelka-restart
on all nodes running Strelka.Alternatively, run
salt -G 'role:so-sensor' cmd.run "so-strelka-restart"
to restart Strelka on all sensors at once.