Actions
Feature #3697
opena command line option for suricata-update that would set downloaded rules to their default state
Effort:
Difficulty:
Label:
Description
When downloading and activating rules, suricata-update applies disable and enable filters for rules, but apparently there is no way to disable the rule if it has been disabled in the original downloaded rule file. However, if the rule has been commented out in the original rule file, it often indicates the fact it is regarded prone to false positives by its authors.
PulledPork addresses this issue nicely and supports -R command line option for that purpose, and this option is very handy for disabling noisy rules (see https://github.com/shirkdog/pulledpork for more details).
Would it be possible to introduce a similar command line option (or configuration file setting) for suricata-update?
Actions