[hidecontent type="logged" desc="隐藏内容:登录后可查看"]
tar xzvf suricata-6.0.0.tar.gz
cd suricata-6.0.0
./configure
make
make install
/usr/local/bin/
,使用中的默认配置/usr/local/etc/suricata/
并将输出到 /usr/local/var/log/suricata
--disable-gccmarch-native
--prefix
=/usr/
/usr/local/
--sysconfdir
=/etc
/usr/local/etc/
--localstatedir
=/var
/usr/local/var/log/suricata
--enable-lua
--enable-geoip
--enable-dpdk
libjansson, libpcap, libpcre2, libmagic, zlib, libyaml
make gcc (or clang) pkg-config
libgeoip, liblua5.1, libhiredis, libevent
rustc, cargo
Not every distro provides Rust packages yet. Rust can also be installed
directly from the Rust project itself::
https://www.rust-lang.org/en-US/install.html
apt-get install build-essential libpcap-dev \
libyaml-0-2 libyaml-dev pkg-config zlib1g zlib1g-dev \
make libmagic-dev libjansson libjansson-dev libpcre2-dev
apt-get install build-essential libpcap-dev \
libnet1-dev libyaml-0-2 libyaml-dev pkg-config zlib1g zlib1g-dev \
libcap-ng-dev libcap-ng0 make libmagic-dev \
libgeoip-dev liblua5.1-dev libhiredis-dev libevent-dev \
python-yaml rustc cargo libpcre2-dev
apt-get install libnetfilter-queue-dev libnetfilter-queue1 \
libnetfilter-log-dev libnetfilter-log1 \
libnfnetlink-dev libnfnetlink0
apt-get install rustc cargo
cargo install --force --debug --version 0.14.1 cbindgen
suricata-stable
始终包含最新稳定版本的 PPA。
使用它:
sudo apt-get install software-properties-common
sudo add-apt-repository ppa:oisf/suricata-stable
sudo apt-get update
sudo apt-get install suricata
sudo apt-get install suricata
root
:
echo "deb http://http.debian.net/debian buster-backports main" > \
/etc/apt/sources.list.d/backports.list
apt-get update
apt-get install suricata -t buster-backports
dnf install epel-release dnf-plugins-core
dnf copr enable @oisf/suricata-7.0
dnf install suricata
yum install epel-release yum-plugin-copr
yum copr enable @oisf/suricata-7.0
yum install suricata
dnf install dnf-plugins-core
dnf copr enable @oisf/suricata-7.0
dnf install suricata
suricata
用户身份运行。/etc/sysconfig/suricata
。suricata-update
如果用户被添加到该组,则无需成为 root 用户即可运行suricata
。/etc/suricata
: 配置目录/var/log/suricata
: 日志目录/var/lib/suricata
:国家目录规则,数据集。systemctl start suricata
systemctl stop suricata
systemctl enable suricata
systemctl reload suricata
yay -S suricata
https://docs.suricata.io/en/latest/install.html
高级用户可以查看高级指南,参见Arch Based。
[/hidecontent]