From: Michael Tremer Date: Thu, 28 Feb 2019 14:28:24 +0000 (+0000) Subject: suricata: Start capture first and then load rules X-Git-Tag: v2.23-core131~117^2~13 X-Git-Url: http://git.ipfire.org/?p=ipfire-2.x.git;a=commitdiff_plain;h=99d75ac72e66928f5218c222b0b3fd8fbfba179f suricata: Start capture first and then load rules Signed-off-by: Michael Tremer Signed-off-by: Stefan Schantl --- diff --git a/config/suricata/suricata.yaml b/config/suricata/suricata.yaml index 369ed2ab2f..083fc54117 100644 --- a/config/suricata/suricata.yaml +++ b/config/suricata/suricata.yaml @@ -698,9 +698,10 @@ detect: toserver-groups: 25 sgh-mpm-context: auto inspection-recursion-limit: 3000 + # If set to yes, the loading of signatures will be made after the capture # is started. This will limit the downtime in IPS mode. - #delayed-detect: yes + delayed-detect: yes prefilter: # default prefiltering setting. "mpm" only creates MPM/fast_pattern