Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature Request: Suricata version override for rulecat? #38

Closed
valorcz opened this issue Jan 3, 2017 · 3 comments
Closed

Feature Request: Suricata version override for rulecat? #38

valorcz opened this issue Jan 3, 2017 · 3 comments

Comments

@valorcz
Copy link

valorcz commented Jan 3, 2017

I am merging Suricata ET rules on a server where Suricata daemon is not present, but I know which version of it runs on the boxes. However, rulecat doesn't use '-enhanced' ruleset in such a case, it goes with '-1.3' only.

Would it be possible to add an option with Suricata version override? Or just an option instructing rulecat to download and use the enhanced ruleset?

@jasonish
Copy link
Owner

jasonish commented Jan 3, 2017

For now you could specify the URL with the --url parameter, that will override the default URL used which does take the Suricata version into account.

@valorcz
Copy link
Author

valorcz commented Jan 3, 2017

Great point, thanks!

jasonish added a commit that referenced this issue Mar 7, 2017
The Suricata version can be forced with --suricata-version.

Github issue:
#38
@jasonish
Copy link
Owner

jasonish commented Mar 7, 2017

There is now a "--suricata-version " command line argument to idstools-rulecat.

Commit:
02db0c6

Included in idstools v0.5.6.

@jasonish jasonish closed this as completed Mar 7, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants