Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to add custom rules to Suricata

    Scheduled Pinned Locked Moved IDS/IPS
    5 Posts 2 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • wgstarksW Offline
      wgstarks
      last edited by

      I've found quite a few posts regarding syntax for custom rules but no discussion of how to actually add the rules. Is it as simple as pasting them into the Defined Custom Rules?

      SafariScreenSnapz080.jpg_thumb
      SafariScreenSnapz080.jpg

      Box: SG-4200

      1 Reply Last reply Reply Quote 0
      • bmeeksB Offline
        bmeeks
        last edited by

        Yep!  That's just a plain vanilla text area web control.  You can copy, paste and edit content in there; then click SAVE when finished.  The custom rule (or rules) will be added to any other rules you have selected from the regular sources.  Each rule should begin on a line by itself.

        Bill

        1 Reply Last reply Reply Quote 0
        • wgstarksW Offline
          wgstarks
          last edited by

          Thanks.

          Is there a way to pass an FQDN or do I need to just list all their IP’s?

          Box: SG-4200

          1 Reply Last reply Reply Quote 0
          • bmeeksB Offline
            bmeeks
            last edited by

            @wgstarks:

            Thanks.

            Is there a way to pass an FQDN or do I need to just list all their IP’s?

            You will need to list the IPs separately.  Snort (the binary part) has no concept of a FQDN.  It does not perform any kind of DNS lookup when analyzing traffic.  Doing that would slow the network down to a crawl.

            Bill

            1 Reply Last reply Reply Quote 0
            • wgstarksW Offline
              wgstarks
              last edited by

              Thanks. Wonder how many IP’s this hosting server has?😏

              Box: SG-4200

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.