Suricata Ruleset¶
The CrowdStrike Falcon Suricata ruleset file will only be downloaded if it has changed since the last interval.
If the ‘interval_hours’ is set to 0, the integration will attempt to download additional content each time the Corelight-update service runs. See Configuration settings
Once downloaded, the ruleset will be processed with the rulesets from all other sources.
Settings¶
crowdstrike_suricata: enabled: false interval_hours: 0