From mboxrd@z Thu Jan 1 00:00:00 1970 From: Stefan Schantl To: development@lists.ipfire.org Subject: [PATCH] suricata: Do not load rules for dnp3 and modbus. Date: Thu, 16 Dec 2021 20:23:36 +0100 Message-ID: <20211216192336.2595-1-stefan.schantl@ipfire.org> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============3653268642891372029==" List-Id: --===============3653268642891372029== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable The parsers for those are disabled in the suricata config so the rules are not needed, on the contrary they massively will spam warnings when launching suricate because of the disabled parsers. Signed-off-by: Stefan Schantl --- config/suricata/suricata-default-rules.yaml | 2 -- 1 file changed, 2 deletions(-) diff --git a/config/suricata/suricata-default-rules.yaml b/config/suricata/su= ricata-default-rules.yaml index 64493e462..d6c358add 100644 --- a/config/suricata/suricata-default-rules.yaml +++ b/config/suricata/suricata-default-rules.yaml @@ -5,13 +5,11 @@ - /usr/share/suricata/rules/app-layer-events.rules - /usr/share/suricata/rules/decoder-events.rules - /usr/share/suricata/rules/dhcp-events.rules - - /usr/share/suricata/rules/dnp3-events.rules - /usr/share/suricata/rules/dns-events.rules - /usr/share/suricata/rules/files.rules - /usr/share/suricata/rules/http-events.rules - /usr/share/suricata/rules/ipsec-events.rules - /usr/share/suricata/rules/kerberos-events.rules - - /usr/share/suricata/rules/modbus-events.rules - /usr/share/suricata/rules/nfs-events.rules - /usr/share/suricata/rules/ntp-events.rules - /usr/share/suricata/rules/smb-events.rules --=20 2.30.2 --===============3653268642891372029==--