Tuesday, January 21, 2014

Snort and Suricata 1.4.7 packages now available!

The following software was recently released:


Suricata 1.4.7

I've packaged these new releases and the new packages have been tested by JP Bourget and David Zawdie.  Thanks, guys!

The new packages are now available in our stable repo.  Please see our Upgrade page for full upgrade instructions:

These updates will do the following:

  • back up each of your existing snort.conf files to snort.conf.bak
  • update Snort
  • back up each of your existing suricata.yaml files to suricata.yaml.bak
  • update Suricata

You'll then need to do the following:

  • apply your local customizations to the new snort.conf or suricata.yaml files
  • update ruleset and restart Snort/Suricata as follows:
    sudo rule-update

Release Notes
Snort is now compiled with --enable-sourcefire.

"sudo soup" upgrade process
Snort and Suricata 1.4.7

Updating ruleset and restarting Snort/Suricata using "sudo rule-update"
If you have any questions or problems, please use our mailing list:

Help Wanted
If you and/or your organization have found value in Security Onion, please consider giving back to the community by joining one of our teams:

We especially need help in answering support questions on the mailing list and IRC channel.  Thanks!


Unknown said...

For future reference, when is the "sudo rule-update" required, only for specific SO updates, or when Snort is updated to newer version? Thanks!

Doug Burks said...

Hi William,

"sudo rule-update" is required when updating Snort to ensure that you get the updated rules specific to your new version of Snort.

If you have further questions, please use our mailing list.

Search This Blog

Featured Post

New Security Onion Online Training Class - Detection Engineering with Security Onion!

We've just added an exciting new course to our online Security Onion 2.4 training catalog! It's called "Detection Engineering w...

Popular Posts

Blog Archive