Suricata not download Rule categories

Nethserver 7.9.2009

good morning community, i just conluded a migration from a server to a newer one, i have a problem with IPS suricata.
I exported the configuration file of the old server through the backup section, I then uploaded that file to the new server and imported the data from the backup (restore-data).

it doesn’t load the rules/filters, i’ve tried uninstalling and installing the packages

yum remove nethserver-suricata nethserver-pulledpork nethserver-evebox -y

below you can see suricata.log

8/7/2021 – 11:12:55 - - This is Suricata version 4.1.10 RELEASE
8/7/2021 – 11:12:56 - - all 4 packet processing threads, 4 management threads initialized, engine started.
8/7/2021 – 11:12:56 - - rule reload starting
8/7/2021 – 11:12:56 - - [ERRCODE: SC_ERR_INVALID_ARGUMENT(13)] - Invalid rule-files configuration section: expected a list of filenames.
8/7/2021 – 11:12:57 - - rule reload complete
8/7/2021 – 11:12:57 - - Signature(s) loaded, Detect thread(s) activated.
8/7/2021 – 11:13:12 - - rule reload starting
8/7/2021 – 11:13:12 - - [ERRCODE: SC_ERR_INVALID_ARGUMENT(13)] - Invalid rule-files configuration section: expected a list of filenames.
8/7/2021 – 11:13:13 - - rule reload complete
8/7/2021 – 11:13:15 - - rule reload starting
8/7/2021 – 11:13:15 - - [ERRCODE: SC_ERR_INVALID_ARGUMENT(13)] - Invalid rule-files configuration section: expected a list of filenames.
8/7/2021 – 11:13:16 - - rule reload complete
8/7/2021 – 11:13:18 - - Signal Received. Stopping engine.
8/7/2021 – 11:13:19 - - (W-Q0) Treated: Pkts 0, Bytes 0, Errors 0
8/7/2021 – 11:13:19 - - (W-Q0) Verdict: Accepted 0, Dropped 0, Replaced 0
8/7/2021 – 11:13:19 - - (W-Q1) Treated: Pkts 0, Bytes 0, Errors 0
8/7/2021 – 11:13:19 - - (W-Q1) Verdict: Accepted 0, Dropped 0, Replaced 0
8/7/2021 – 11:13:19 - - (W-Q2) Treated: Pkts 0, Bytes 0, Errors 0
8/7/2021 – 11:13:19 - - (W-Q2) Verdict: Accepted 0, Dropped 0, Replaced 0
8/7/2021 – 11:13:19 - - (W-Q3) Treated: Pkts 0, Bytes 0, Errors 0
8/7/2021 – 11:13:19 - - (W-Q3) Verdict: Accepted 0, Dropped 0, Replaced 0

@support_team
Can somebody help?

You need to execute /sbin/e-smith/signal-event -j nethserver-pulledpork-save.

Check inside /var/log/messages for errors.

2 Likes

apparently not… but there is a write error after downloading…

[root@srvmail ~]# tail /var/log/messages
Jul  9 17:38:39 srvmail esmith::event[21079]:  @_/        /  66\_  and the PulledPork Team!
Jul  9 17:38:39 srvmail esmith::event[21079]:    |    \   \   _(")
Jul  9 17:38:39 srvmail esmith::event[21079]:     \   /-| ||'--'  Rules give me wings!
Jul  9 17:38:39 srvmail esmith::event[21079]:      \_\  \_\\
Jul  9 17:38:39 srvmail esmith::event[21079]: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Jul  9 17:38:39 srvmail esmith::event[21079]: 
Jul  9 17:38:39 srvmail esmith::event[21079]: Error downloading https://rules.emergingthreats.net/open-nogpl/suricata-4.0/emerging.rules.tar.gz.md5: 500 write failed:  [ 500 ]
Jul  9 17:38:39 srvmail esmith::event[21079]: Checking latest MD5 for emerging.rules.tar.gz....
Jul  9 17:38:39 srvmail esmith::event[21079]: Action: /etc/e-smith/events/nethserver-pulledpork-save/S30nethserver-pulledpork-apply SUCCESS [0.499576]
Jul  9 17:38:39 srvmail esmith::event[21079]: Event: nethserver-pulledpork-save SUCCESS

Rules are downloaded in /tmp.
Can you write a file there? If it is a disk full, you should have more problems.
Please show the output of ls -ld /tmp.

seems to me to be correct…
drwxrwxrwt. 21 root root 4096 9 lug 18.23 /tmp

I just did a wget and it gives me an error, so I think I have something wrong with my connection, maybe there are restrictions in my firewall at the beginning of the network… now I check.