Installing & Configuring Suricata

Поділитися
Вставка
  • Опубліковано 29 січ 2025

КОМЕНТАРІ • 54

  • @DahDaveman
    @DahDaveman Рік тому +1

    This video can't get enough likes! You helped me work out the bugs in my suricata install, thank you!

  • @primescope6874
    @primescope6874 2 роки тому +6

    Great video. You are producing some excellent content as I'm studying cybersecurity. Many thanks and much appreciated. Keep up the good work.

  • @armanqusham5345
    @armanqusham5345 Рік тому +1

    Thank you for this detailed video on how to install suricata and configure it. Really helped with my final year project in uni

  • @ChapalPuteh_
    @ChapalPuteh_ Рік тому +9

    btw, the rules folder for freshly ubuntu vm are stored in usr/share/suricata/rules .. others will face this error when they want to edit the local.rules. Just simply change the mentioned directories ..

    • @umarfarouk7764
      @umarfarouk7764 Рік тому +1

      Thanks a million

    • @hugo_guzman
      @hugo_guzman 10 місяців тому

      weird, I recently installed ubuntu 22.04, and Suricata, and the rules files are in the /var/lib/suricata/rules directory:
      sudo ls -la /var/lib/suricata/rules/
      total 27580
      drwxr-x--- 2 root root 4096 Mar 27 19:45 .
      drwxr-xr-x 4 root root 4096 Mar 27 19:45 ..
      -rw-r--r-- 1 root root 3228 Mar 27 19:45 classification.config
      -rw-r--r-- 1 root root 28229228 Mar 27 19:45 suricata.rules

  • @bertinndayizeye_Tino
    @bertinndayizeye_Tino 25 днів тому

    Thanks alot for this video. It helped me to do my first configuration of Suricata

  • @MrE-h7n
    @MrE-h7n Місяць тому

    New Sub!!! Up and running 2024, so much better then snort

  • @samiehessi8163
    @samiehessi8163 2 роки тому +2

    This was indeed a high quality content. Thanks!

  • @oshinubirotimirasheed3131
    @oshinubirotimirasheed3131 Рік тому

    thank you for sharing this knowledge I look forward to taking more classes from you.

  • @tyalva1814
    @tyalva1814 Рік тому

    I get an error for the update at 11:14 mark [ERRCODE: SC_ERR_CONF_YAML_ERROR(242)] - The configuration file must begin with the following two lines: %YAML 1.1 and ---

  • @jiesikkoo7874
    @jiesikkoo7874 7 місяців тому

    Hello, firstly thanks for the video you provided its a big help but i am facing a problem is that the rules i set customly for icmp ping its not working and not generating any alert as you does why is it? your response will be very helpful

  • @richardbranson8117
    @richardbranson8117 2 роки тому +1

    love this man

  • @FredPhillips32169
    @FredPhillips32169 2 роки тому

    Brilliant having the "Register for Part 2" pop up right after an easily edited whoopsie.

  • @m-electronics5977
    @m-electronics5977 Рік тому

    First: A big thanksgiving for that great video(s) about Suricata und IDS, now I unterstand it also👍👍👍
    But when I want to monitor(not Control) all the traffic that are going in and out of my network I must run the Suricata IDS on a Firewall or router or something like this where the traffic goes trough?

  • @rafaelhengky8915
    @rafaelhengky8915 Рік тому

    Hi. I managed to install Suricata on VMWare and it has successfully captured ping/icmp packet destinate to it. But it didn't capture any network traffic. Any suggestion?

  • @tareq06
    @tareq06 Рік тому

    Thank you sir... You made my day

  • @hassanahmed87987
    @hassanahmed87987 2 роки тому +1

    When you'll upload next video of suricata??

  • @Akira29H
    @Akira29H 5 днів тому

    Any gui?

  • @firebeasth8009
    @firebeasth8009 2 роки тому +2

    Thanks for this!

    • @sexualsmile
      @sexualsmile 2 роки тому

      Its finally here
      ua-cam.com/users/shortsNlhBppjxnqs?feature=share

  • @jibraelaryaanentertainment1263
    @jibraelaryaanentertainment1263 5 місяців тому

    Just brilliant!!

  • @slevinhyde3212
    @slevinhyde3212 10 місяців тому

    Definitely is quality content

  • @hshs4861-c9r
    @hshs4861-c9r 2 роки тому +1

    Really great !

  • @Polalis12
    @Polalis12 2 роки тому

    When I install suricata I do not have config files in /etc/suricata. How to fix that?

  • @0xr1kk07
    @0xr1kk07 2 роки тому +2

    Thank you!

  • @raymencliff4296
    @raymencliff4296 2 роки тому +1

    I like always your video

  • @salindabandara4471
    @salindabandara4471 2 роки тому +1

    Hello sir. I try update my rule set in suricata. But after give the update-suricata command i got the following error. Err Code: SC_ERR_CONF_YAML_ERROR(242)
    Can you help me to how to handle this error

    • @dhehibiali3283
      @dhehibiali3283 2 роки тому +2

      Hi Salinda
      Did you find a solution for this error
      thank you

  • @ae_world_Akash
    @ae_world_Akash 2 роки тому +1

    Hi sir I am new subscriber

  • @dedisubandi3391
    @dedisubandi3391 Рік тому

    Great video!!!!!

  • @m-electronics5977
    @m-electronics5977 Рік тому

    But Suricata doesn't have a Web UI? I think I saw something about that

  • @onecarry1532
    @onecarry1532 2 роки тому

    Beautiful!

  • @OthmanAlikhan
    @OthmanAlikhan 2 роки тому

    Thanks for the video =)

  • @dedisubandi3391
    @dedisubandi3391 Рік тому

    Great video..!!!!

  • @goodboy-mn2qp
    @goodboy-mn2qp 8 місяців тому

    it's very helpful

  • @Tottte
    @Tottte 10 місяців тому

    If there are idiots out there like me. You are not supposed to write "1" in the beginning of the rule. You can check the there is any syntax error of the rule with "suricata -c /etc/suricata/suricata.yaml -i [INTERFACE]"

  • @0xr1kk07
    @0xr1kk07 2 роки тому +4

    Hi sir, can you also do a tutorial on ELK installation please. Thank you

    • @kryptonic010
      @kryptonic010 2 роки тому +2

      I agree. You know we like to see pretty graphs.

  • @sotecluxan4221
    @sotecluxan4221 2 роки тому +1

    Great!

  • @marcostiantoni
    @marcostiantoni Рік тому +1

    Thank you for the video. I have the rules only in /usr/share/suricata/rules. How can I get in them in default-rule-path: /var/lib/suricata/rules?

    • @swarajyamdeepakraj-kz4pd
      @swarajyamdeepakraj-kz4pd Рік тому

      i am also facing the same problem. How you managed>??

    • @marcosfleitas9605
      @marcosfleitas9605 11 місяців тому +1

      actually all your rules that are in /usr/share/suricata/rules are compiled in /var/lib/suricata/rules suricata.rules

  • @FredPhillips32169
    @FredPhillips32169 2 роки тому

    External_Net != Home_net what about broadcast & multicast?

    • @8080VB
      @8080VB 2 роки тому

      uhh? if you provide the correct gateway/CIDR . everything should be good .

  • @FredPhillips32169
    @FredPhillips32169 2 роки тому

    If you are trying to make the flow ID lees predictable then don't use the default seed of 0.

  • @goodboy-mn2qp
    @goodboy-mn2qp 8 місяців тому

    عاشت ايدك

  • @ChapalPuteh_
    @ChapalPuteh_ Рік тому

    tq sir

  • @atanumondal7879
    @atanumondal7879 2 роки тому

    14:00

  • @MaxesSig8
    @MaxesSig8 2 роки тому +1

    first comment

  • @fairyTaleAnimations
    @fairyTaleAnimations 2 роки тому +1

    F

  • @reskun
    @reskun 11 місяців тому

    would give 100 likes if I could

  • @whothefoxcares
    @whothefoxcares Рік тому

    I saw the logs. I'm a lumberjack and you're not 🙂 zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz.