Can I use suricata-update to update rules excluded from suricata-update list-sources above? Such as URL haus rules from URLhaus | API.
If yes, how to update these rules? Do I need to download rulesets before update rules?
I want to update some rules which excluded from suricata-update list-sources, I don’t think I can update these rules with enable-source if they are not listed.
Hi @CoolerAndy !
Thank you for reaching out. In any case, we shuld not have an exception traceback s this requires a bug report. Could you please submit a bug report on Overview - Suricata-Update - Open Information Security Foundation with the exact steps that you used to reach this traceback and the version of suricata-update you’re using? Perhaps, that can help us debug the issue you’re having too.
I’ll be happy to take a look into this for you.
Thank you very much!
Thanks for your reply. I need to apologize I can’t find the “submit” button on Overview - Suricata-Update - Open Information Security Foundation, all I can do is to view descriptions of bugs. Anyway, my suricata-update version is 1.2.2 (rev: 9a44e83) (suricata version 4.1.4)and update steps are attached below
It looks like you did a sequence of events that created a source without a URL, so its looking to the index for the URL for that source, but it doesn’t exist in the index.
See if you can remove the source in question:
suricata-update remove-source feodotracker-botnet
Make sure suricata-update can run without issues.
Then try re-adding that ruleset with a command like: