# Suricata-update add-source for previously disabled source

**URL:** <https://forum.suricata.io/t/suricata-update-add-source-for-previously-disabled-source/442>\
**Category:** Help\
**Created:** [July 24, 2020, 11:11pm UTC](https://forum.suricata.io/t/suricata-update-add-source-for-previously-disabled-source/442 "2020-07-24T23:11:12Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![babarshariff](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/babarshariff/32/770_2.png) [@babarshariff](https://forum.suricata.io/u/babarshariff)\
**Post date:** [May 12, 2021, 3:53pm UTC](https://forum.suricata.io/t/suricata-update-add-source-for-previously-disabled-source/442/5 "2021-05-12T15:53:23Z")

</div>

Hi, Was this ever fixed? As well as issue noted by OP, it seems `list-sources` doesn’t list sources added via `add-source`.  
This is on `version 1.1.0 (rev: 63493db)`, the version pip3 installs (the dummy source at the end is an override of env variable SOURCE\_INDEX\_URL):

```
[root@corelight]# suricata-update add-source foo https://bar.com/baz.rules.tar.gz --suricata-conf=/var/corelight/suricata/.suricata.yaml --suricata=/usr/bin/corelight-suricata -D /etc/corelight/suricata-update -v
12/5/2021 -- 15:44:16 - <Debug> -- This is suricata-update version 1.1.0 (rev: 63493db); Python: 3.6.8 (default, Aug 13 2020, 07:46:32) - [GCC 4.8.5 20150623 (Red Hat 4.8.5-39)]
12/5/2021 -- 15:44:16 - <Debug> -- Setting configuration value subcommand -> add-source
12/5/2021 -- 15:44:16 - <Debug> -- Setting configuration value verbose -> True
12/5/2021 -- 15:44:16 - <Debug> -- Setting data directory to /etc/corelight/suricata-update
12/5/2021 -- 15:44:16 - <Debug> -- Setting configuration value suricata-conf -> /var/corelight/suricata/.suricata.yaml
12/5/2021 -- 15:44:16 - <Debug> -- Setting configuration value suricata -> /usr/bin/corelight-suricata
12/5/2021 -- 15:44:16 - <Debug> -- Setting configuration value version -> False
12/5/2021 -- 15:44:16 - <Debug> -- Setting configuration value name -> foo
12/5/2021 -- 15:44:16 - <Debug> -- Setting configuration value url -> https://bar.com/baz.rules.tar.gz
12/5/2021 -- 15:44:16 - <Debug> -- Setting configuration value no-checksum -> True
12/5/2021 -- 15:44:16 - <Debug> -- Setting configuration value func -> <function add_source at 0x7f071bddd730>
12/5/2021 -- 15:44:16 - <Info> -- Found Suricata version 5.0.3-corelight at /usr/bin/corelight-suricata.
[root@corelight]# suricata-update disable-source foo --suricata-conf=/var/corelight/suricata/.suricata.yaml --suricata=/usr/bin/corelight-suricata -D /etc/corelight/suricata-update -v
12/5/2021 -- 15:44:40 - <Debug> -- This is suricata-update version 1.1.0 (rev: 63493db); Python: 3.6.8 (default, Aug 13 2020, 07:46:32) - [GCC 4.8.5 20150623 (Red Hat 4.8.5-39)]
12/5/2021 -- 15:44:40 - <Debug> -- Setting configuration value subcommand -> disable-source
12/5/2021 -- 15:44:40 - <Debug> -- Setting configuration value verbose -> True
12/5/2021 -- 15:44:40 - <Debug> -- Setting data directory to /etc/corelight/suricata-update
12/5/2021 -- 15:44:40 - <Debug> -- Setting configuration value suricata-conf -> /var/corelight/suricata/.suricata.yaml
12/5/2021 -- 15:44:40 - <Debug> -- Setting configuration value suricata -> /usr/bin/corelight-suricata
12/5/2021 -- 15:44:40 - <Debug> -- Setting configuration value version -> False
12/5/2021 -- 15:44:40 - <Debug> -- Setting configuration value name -> foo
12/5/2021 -- 15:44:40 - <Debug> -- Setting configuration value func -> <function disable_source at 0x7f2da1a4ce18>
12/5/2021 -- 15:44:40 - <Info> -- Found Suricata version 5.0.3-corelight at /usr/bin/corelight-suricata.
12/5/2021 -- 15:44:40 - <Debug> -- Renaming /etc/corelight/suricata-update/update/sources/foo.yaml to /etc/corelight/suricata-update/update/sources/foo.yaml.disabled.
12/5/2021 -- 15:44:40 - <Info> -- Source foo has been disabled
[root@corelight]# suricata-update add-source foo https://bar.com/baz.rules.tar.gz --suricata-conf=/var/corelight/suricata/.suricata.yaml --suricata=/usr/bin/corelight-suricata -D /etc/corelight/suricata-update -v
12/5/2021 -- 15:45:06 - <Debug> -- This is suricata-update version 1.1.0 (rev: 63493db); Python: 3.6.8 (default, Aug 13 2020, 07:46:32) - [GCC 4.8.5 20150623 (Red Hat 4.8.5-39)]
12/5/2021 -- 15:45:06 - <Debug> -- Setting configuration value subcommand -> add-source
12/5/2021 -- 15:45:06 - <Debug> -- Setting configuration value verbose -> True
12/5/2021 -- 15:45:06 - <Debug> -- Setting data directory to /etc/corelight/suricata-update
12/5/2021 -- 15:45:06 - <Debug> -- Setting configuration value suricata-conf -> /var/corelight/suricata/.suricata.yaml
12/5/2021 -- 15:45:06 - <Debug> -- Setting configuration value suricata -> /usr/bin/corelight-suricata
12/5/2021 -- 15:45:06 - <Debug> -- Setting configuration value version -> False
12/5/2021 -- 15:45:06 - <Debug> -- Setting configuration value name -> foo
12/5/2021 -- 15:45:06 - <Debug> -- Setting configuration value url -> https://bar.com/baz.rules.tar.gz
12/5/2021 -- 15:45:06 - <Debug> -- Setting configuration value no-checksum -> True
12/5/2021 -- 15:45:06 - <Debug> -- Setting configuration value func -> <function add_source at 0x7fd5fe5f4730>
12/5/2021 -- 15:45:06 - <Info> -- Found Suricata version 5.0.3-corelight at /usr/bin/corelight-suricata.
12/5/2021 -- 15:45:06 - <Error> -- A source with name foo already exists.
[root@corelight]# suricata-update enable-source foo --suricata-conf=/var/corelight/suricata/.suricata.yaml --suricata=/usr/bin/corelight-suricata -D /etc/corelight/suricata-update -v
12/5/2021 -- 15:45:13 - <Debug> -- This is suricata-update version 1.1.0 (rev: 63493db); Python: 3.6.8 (default, Aug 13 2020, 07:46:32) - [GCC 4.8.5 20150623 (Red Hat 4.8.5-39)]
12/5/2021 -- 15:45:13 - <Debug> -- Setting configuration value subcommand -> enable-source
12/5/2021 -- 15:45:13 - <Debug> -- Setting configuration value verbose -> True
12/5/2021 -- 15:45:13 - <Debug> -- Setting data directory to /etc/corelight/suricata-update
12/5/2021 -- 15:45:13 - <Debug> -- Setting configuration value suricata-conf -> /var/corelight/suricata/.suricata.yaml
12/5/2021 -- 15:45:13 - <Debug> -- Setting configuration value suricata -> /usr/bin/corelight-suricata
12/5/2021 -- 15:45:13 - <Debug> -- Setting configuration value version -> False
12/5/2021 -- 15:45:13 - <Debug> -- Setting configuration value name -> foo
12/5/2021 -- 15:45:13 - <Debug> -- Setting configuration value params -> []
12/5/2021 -- 15:45:13 - <Debug> -- Setting configuration value func -> <function enable_source at 0x7fc0e03debf8>
12/5/2021 -- 15:45:13 - <Info> -- Found Suricata version 5.0.3-corelight at /usr/bin/corelight-suricata.
12/5/2021 -- 15:45:13 - <Info> -- Re-enabling previously disabled source for foo.
12/5/2021 -- 15:45:13 - <Error> -- Unknown source: foo
[root@corelight]# suricata-update list-sources --suricata-conf=/var/corelight/suricata/.suricata.yaml --suricata=/usr/bin/corelight-suricata -D /etc/corelight/suricata-update -v
12/5/2021 -- 15:45:26 - <Debug> -- This is suricata-update version 1.1.0 (rev: 63493db); Python: 3.6.8 (default, Aug 13 2020, 07:46:32) - [GCC 4.8.5 20150623 (Red Hat 4.8.5-39)]
12/5/2021 -- 15:45:26 - <Debug> -- Setting configuration value subcommand -> list-sources
12/5/2021 -- 15:45:26 - <Debug> -- Setting configuration value verbose -> True
12/5/2021 -- 15:45:26 - <Debug> -- Setting data directory to /etc/corelight/suricata-update
12/5/2021 -- 15:45:26 - <Debug> -- Setting configuration value suricata-conf -> /var/corelight/suricata/.suricata.yaml
12/5/2021 -- 15:45:26 - <Debug> -- Setting configuration value suricata -> /usr/bin/corelight-suricata
12/5/2021 -- 15:45:26 - <Debug> -- Setting configuration value version -> False
12/5/2021 -- 15:45:26 - <Debug> -- Setting configuration value free -> False
12/5/2021 -- 15:45:26 - <Debug> -- Setting configuration value func -> <function list_sources at 0x7f31ac5b1a60>
12/5/2021 -- 15:45:26 - <Info> -- Found Suricata version 5.0.3-corelight at /usr/bin/corelight-suricata.
Name: foobar
  Vendor: Am I vendor
  Summary: Who am I
  License: MIT
```

---

_[View the full topic](https://forum.suricata.io/t/suricata-update-add-source-for-previously-disabled-source/442)._
