๐ฆInstalling and Configuring Network Based IDS In Ubuntu: Suricata
Install Suricata In Ubuntu
$ sudo apt install suricataModify The Configuration File
sudo gedit /etc/suricata/suricata.yamlIn the Line no 15 Change the HOME_NET IP address subnet to your machines IP subnet
In the Line no 580 change the Interface from eth0 to your local interface name (In my case it is enp0s3)
In the Line no 661 change the Interface from eth0 to your local interface name (In my case it is enp0s3)
In the Line no 129 change the community-id from false to true
You can add custom rules after Line no 1875
Update Suricata
$ sudo suricata-updateList Suricata Rules
$ sudo ls -al /var/lib/suricata/rules/
Download Rulesets
$ sudo suricata-update list-sources
Enable A Source
$ sudo suricata-update enable-source malsilo/win-malware
Test The Suricata Configuration File
$ sudo suricata -T -c /etc/suricata/suricata.yaml -vRun Suricata
$ sudo systemctl start suricata.serviceView The Logs
$ ls -al /var/log/suricataTest If The Data Is Logged Or Not?
Make a Curl Request
$ surl http://testmynids.org/uid/index.htmlView The Logs
$ sudo cat /var/log/suricata/fast.logSuricata Custom Rules
Create a Custom Rule
$ sudo gedit /etc/suricata/rules/local.rulesAdd the Below Line In local.rules file
alert icmp any any -> $HOME_NET (msg:"icmp ping"; sid:1; rev:1;)Add the local.rules file name/path in suricata.yaml file
Add the below text after the Line no 1875 in suricata.yaml file
- /etc/suricata/rules/local.rulesSave the file and exit
Install jq
sudo apt-get install jqView the Latest Logs
$ sudo tail -f /var/log/suricata/eve.json | jq 'select(.event_type=="alert")'Last updated
Was this helpful?