limit-noproc: true
# Use landlock security module under Linux
landlock:
- enabled: no
+ enabled: yes
directories:
write:
- /run
# /usr and /etc folders are added to read list to allow
# file magic to be used.
read:
- - /usr/share/misc/magic.mgc
+ - /etc/suricata
+ - /usr/share/misc
- /usr/share/suricata
- /var/ipfire/suricata
- /var/lib/suricata