path: root/doc/userguide/suricatasc.1
diff options
Diffstat (limited to 'doc/userguide/suricatasc.1')
1 files changed, 251 insertions, 0 deletions
diff --git a/doc/userguide/suricatasc.1 b/doc/userguide/suricatasc.1
new file mode 100644
index 0000000..2b41ae0
--- /dev/null
+++ b/doc/userguide/suricatasc.1
@@ -0,0 +1,251 @@
+.\" Man page generated from reStructuredText.
+. rst2man-indent-level 0
+.de1 rstReportMargin
+\\$1 \\n[an-margin]
+level \\n[rst2man-indent-level]
+level margin: \\n[rst2man-indent\\n[rst2man-indent-level]]
+.de1 INDENT
+.\" .rstReportMargin pre:
+. RS \\$1
+. nr rst2man-indent\\n[rst2man-indent-level] \\n[an-margin]
+. nr rst2man-indent-level +1
+.\" .rstReportMargin post:
+. RE
+.\" indent \\n[an-margin]
+.\" old: \\n[rst2man-indent\\n[rst2man-indent-level]] rst2man-indent-level -1
+.\" new: \\n[rst2man-indent\\n[rst2man-indent-level]] \\n[rst2man-indent\\n[rst2man-indent-level]]u
+.TH "SURICATASC" "1" "Feb 08, 2024" "7.0.3" "Suricata"
+suricatasc \- Tool to interact via unix socket
+Suricata socket control tool
+.INDENT 0.0
+.B shutdown
+Shut Suricata instance down.
+.INDENT 0.0
+.B command\-list
+List available commands.
+.INDENT 0.0
+.B help
+Get help about the available commands.
+.INDENT 0.0
+.B version
+Print the version of Suricata instance.
+.INDENT 0.0
+.B uptime
+Display the uptime of Suricata.
+.INDENT 0.0
+.B running\-mode
+Display running mode. This can either be \fIworkers\fP, \fIautofp\fP or \fIsingle\fP\&.
+.INDENT 0.0
+.B capture\-mode
+Display the capture mode. This can be either of \fIPCAP_DEV\fP,
+.INDENT 0.0
+.B conf\-get <variable>
+Get configuration value for a given variable. Variable to be provided can be
+either of the configuration parameters that are written in suricata.yaml.
+.INDENT 0.0
+.B dump\-counters
+Dump Suricata\(aqs performance counters.
+.INDENT 0.0
+.B ruleset\-reload\-rules
+Reload the ruleset and wait for completion.
+.INDENT 0.0
+.B reload\-rules
+Alias .. describe \fIruleset\-reload\-rules\fP\&.
+.INDENT 0.0
+.B ruleset\-reload\-nonblocking
+Reload ruleset and proceed without waiting.
+.INDENT 0.0
+.B ruleset\-reload\-time
+Return time of last reload.
+.INDENT 0.0
+.B ruleset\-stats
+Display the number of rules loaded and failed.
+.INDENT 0.0
+.B ruleset\-failed\-rules
+Display the list of failed rules.
+.INDENT 0.0
+.B register\-tenant\-handler <id> <htype> [hargs]
+Register a tenant handler with the specified mapping.
+.INDENT 0.0
+.B unregister\-tenant\-handler <id> <htype> [hargs]
+Unregister a tenant handler with the specified mapping.
+.INDENT 0.0
+.B register\-tenant <id> <filename>
+Register tenant with a particular ID and filename.
+.INDENT 0.0
+.B reload\-tenant <id> [filename]
+Reload a tenant with specified ID. A filename to a tenant yaml can be
+specified. If it is omitted, the original yaml that was used to load
+/ last reload the tenant is used.
+.INDENT 0.0
+.B reload\-tenants
+Reload all registered tenants by reloading their yaml.
+.INDENT 0.0
+.B unregister\-tenant <id>
+Unregister tenant with a particular ID.
+.INDENT 0.0
+.B add\-hostbit <ipaddress> <hostbit> <expire>
+Add hostbit on a host IP with a particular bit name and time of expiry.
+.INDENT 0.0
+.B remove\-hostbit <ipaddress> <hostbit>
+Remove hostbit on a host IP with specified IP address and bit name.
+.INDENT 0.0
+.B list\-hostbit <ipaddress>
+List hostbit for a particular host IP.
+.INDENT 0.0
+.B reopen\-log\-files
+Reopen log files to be run after external log rotation.
+.INDENT 0.0
+.B memcap\-set <config> <memcap>
+Update memcap value of a specified item.
+.INDENT 0.0
+.B memcap\-show <config>
+Show memcap value of a specified item.
+.INDENT 0.0
+.B memcap\-list
+List all memcap values available.
+.INDENT 0.0
+.B pcap\-file <file> <dir> [tenant] [continuous] [delete\-when\-done]
+Add pcap files to Suricata for sequential processing. The generated
+log/alert files will be put into the directory specified as second argument.
+Make sure to provide absolute path to the files and directory. It is
+acceptable to add multiple files without waiting the result.
+.INDENT 0.0
+.B pcap\-file\-continuous <file> <dir> [tenant] [delete\-when\-done]
+Add pcap files to Suricata for sequential processing. Directory will be
+monitored for new files being added until there is a use of
+\fBpcap\-interrupt\fP or directory is moved or deleted.
+.INDENT 0.0
+.B pcap\-file\-number
+Number of pcap files waiting to get processed.
+.INDENT 0.0
+.B pcap\-file\-list
+List of queued pcap files.
+.INDENT 0.0
+.B pcap\-last\-processed
+Processed time of last file in milliseconds since epoch.
+.INDENT 0.0
+.B pcap\-interrupt
+Terminate the current state by interrupting directory processing.
+.INDENT 0.0
+.B pcap\-current
+Currently processed file.
+Please visit Suricata\(aqs support page for information about submitting
+bugs or feature requests.
+.INDENT 0.0
+.IP \(bu 2
+Suricata Home Page
+.INDENT 2.0
+.INDENT 3.5
+.IP \(bu 2
+Suricata Support Page
+.INDENT 2.0
+.INDENT 3.5
+2016-2024, OISF
+.\" Generated by docutils manpage writer.