# Suricata not loading rules

**URL:** <https://forum.suricata.io/t/suricata-not-loading-rules/1348>\
**Category:** Help\
**Created:** [May 4, 2021, 10:30pm UTC](https://forum.suricata.io/t/suricata-not-loading-rules/1348 "2021-05-04T22:30:09Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ora](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ora/32/766_2.png) [@ora](https://forum.suricata.io/u/ora)\
**Post date:** [May 4, 2021, 10:30pm UTC](https://forum.suricata.io/t/suricata-not-loading-rules/1348/1 "2021-05-04T22:30:10Z")

</div>

Hello,  
I installed Suricata, enabled etpro and did the suricata-update, it ran fine without issues. Rule file was compiled into

-rw-r–r-- 1 root suricata 44133288 May 4 22:16 /var/lib/suricata/rules/suricata.rules

When I run suricata, it gives me this:

4/5/2021 – 22:24:42 - - stats output device (regular) initialized: stats.log  
4/5/2021 – 22:24:42 - - Running in live mode, activating unix socket  
4/5/2021 – 22:24:42 - - [ERRCODE: SC\_ERR\_FOPEN(44)] - could not open: “/var/lib/suricata/rules/classification.config”: Permission denied  
4/5/2021 – 22:24:42 - - [ERRCODE: SC\_ERR\_OPENING\_FILE(40)] - please check the “classification-file” option in your suricata.yaml file  
4/5/2021 – 22:24:42 - - [ERRCODE: SC\_ERR\_NO\_RULES(42)] - No rule files match the pattern /var/lib/suricata/rules/suricata.rules  
4/5/2021 – 22:24:42 - - [ERRCODE: SC\_ERR\_NO\_RULES\_LOADED(43)] - 1 rule files specified, but no rules were loaded!  
4/5/2021 – 22:24:42 - - Threshold config parsed: 0 rule(s) found  
4/5/2021 – 22:24:42 - - 0 signatures processed. 0 are IP-only rules, 0 are inspecting pa

Tried everything, dir and file permissions, no luck. Everything seems to be in the right place. Suricata is running as root so that cause permission issues. No errors on update, but it just won’t load. Any ideas? TIA

---

<div class="post-metadata">

**Author:** ![ish](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ish/32/8_2.png) [@ish](https://forum.suricata.io/u/ish)\
**Post date:** [May 4, 2021, 10:39pm UTC](https://forum.suricata.io/t/suricata-not-loading-rules/1348/2 "2021-05-04T22:39:44Z")

</div>

How did you install Suricata? From source? RPM? PPA? Can you check the permissions on the directory `/var/lib/suricata/rules` as well.

---

<div class="post-metadata">

**Author:** ![ora](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ora/32/766_2.png) [@ora](https://forum.suricata.io/u/ora)\
**Post date:** [May 4, 2021, 10:52pm UTC](https://forum.suricata.io/t/suricata-not-loading-rules/1348/3 "2021-05-04T22:52:56Z")

</div>

Installed from rpm (suricata-6.0.2-1.el7.x86\_64)

drwxr-sr-x 2 root suricata 4096 May 4 22:43 rules  
drwxr-sr-x 4 root suricata 4096 Apr 29 20:40 update

It’s running as root so perm shouldn’t be an issue unless there is some caveat I’m not aware of.

Oddly the rule file is created with 600  
-rw------- 1 root suricata 44171023 May 4 22:49 suricata.rules

But when I change to 644 it seems to work on et but not etpro

If it’s running as root, why does this matter? Is there a way to create the rule files with necessary permissions? Also, does suricata service need to be restarted after updating or it takes effect? Thanks

---

<div class="post-metadata">

**Author:** ![ish](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ish/32/8_2.png) [@ish](https://forum.suricata.io/u/ish)\
**Post date:** [May 4, 2021, 11:00pm UTC](https://forum.suricata.io/t/suricata-not-loading-rules/1348/4 "2021-05-04T23:00:21Z")

</div>

When using the RPM and starting Suricata with `systemctl`, Suricata will actually run as the `suricata` user, not root. So that is something to be aware of.

Anyways, this should help reset the permissions:

```auto
chmod 2770 /var/lib/suricata
chown -R root:suricata /var/lib/suricata

```

---

<div class="post-metadata">

**Author:** ![ora](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ora/32/766_2.png) [@ora](https://forum.suricata.io/u/ora)\
**Post date:** [May 4, 2021, 11:02pm UTC](https://forum.suricata.io/t/suricata-not-loading-rules/1348/5 "2021-05-04T23:02:29Z")

</div>

Thanks, that’s helpful! So it would make sense to add to the update cronjob the permission bits then. Once update runs, does the engine need to be restarted?

---

<div class="post-metadata">

**Author:** ![ish](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ish/32/8_2.png) [@ish](https://forum.suricata.io/u/ish)\
**Post date:** [May 4, 2021, 11:04pm UTC](https://forum.suricata.io/t/suricata-not-loading-rules/1348/6 "2021-05-04T23:04:33Z")

</div>

The engine needs to be restarted or sent a SIGUSR2 to reload the rules.

The idea with the RPM and the `2770` mode on `/var/lib/suricata` is that you can run `suricata-update` as root, or as a user in the `suricata` group to avoid using root altogether. I’ve never seen a need to update permissions as part of the cronjob, at least not on a default CentOS 8 install with default umasks, etc.

---

<div class="post-metadata">

**Author:** ![ora](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ora/32/766_2.png) [@ora](https://forum.suricata.io/u/ora)\
**Post date:** [May 4, 2021, 11:08pm UTC](https://forum.suricata.io/t/suricata-not-loading-rules/1348/7 "2021-05-04T23:08:04Z")

</div>

Got it. Thanks for your help!
