Suricata Ruleset

The CrowdStrike Falcon Suricata ruleset file will only be downloaded if it has changed since the last interval.

If the ‘interval_hours’ is set to 0, the integration will attempt to download additional content each time the Corelight-update service runs. See Global configuration and policy settings

Once downloaded, the ruleset will be processed with the rulesets from all other sources.

Settings

crowdstrike_suricata:
  enabled:                   false
  interval_hours:            0