Skip to content
Discussion options

You must be logged in to vote

In the suricata containers there are actually two suricata binaries, one that is used for live capture (and is given greater capabilities/permissions) and another that is used for "offline" stuff like PCAP analysis, rule updates, etc. This is done for security hardening reasons.

The solution is to add the argument --suricata /usr/bin/suricata-offline to calls to tools like suricata-update.

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by mmguero
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
suricata Relating to Malcolm's use of Suricata
2 participants
Converted from issue

This discussion was converted from issue #613 on March 12, 2025 14:06.