配suricata插件
cd /opt/arkime/etc/vim config.ini搜索关键词pluginsDir,在面新增如下内容
# Add suricata.so to your plugins line, or add a new plugins lineplugins=suricata.so# suricataAlertFile should be the full path to your alert.json or eve.json filesuricataAlertFile=/var/log/suricata/eve.jsonsuricataExpireMinutes=60
配置arkime读取suricata数据修改eve.json权限
chmod o+r /var/log/suricata/eve.json
如果提示没此文件运行以下suricata就有这个文件了
修改dorpUser cd /opt/arkime/etc/ vim config.ini搜索关键词dropUser,修改为root,