FreshPorts -- The Place For Ports If you buy from Amazon USA, please support us by using this link.
Follow us
Blog
Twitter

I am looking for an LTO tape library. Do you have one to spare?
Port details
suricata High Performance Network IDS, IPS and Security Monitoring engine
2.0.4 security on this many watch lists=8 search for ports that depend on this port
Maintained by: koobs@FreeBSD.org search for ports maintained by this maintainer
Port Added: 01 Sep 2010 15:32:48
License: GPLv2


The Suricata Engine is an Open Source Next Generation Intrusion Detection and
Prevention Engine developed by the Open Information Security Foundation (OISF).

This engine is not intended to just replace or emulate the existing tools in
the industry, but will bring new ideas and technologies to the field.

OISF is part of and funded by the Department of Homeland Security's Directorate
for Science and Technology HOST program (Homeland Open Security Technology),
by the Navy's Space and Naval Warfare Systems Command (SPAWAR), as well as
through the very generous support of the members of the OISF Consortium.

More information about the Consortium is available, as well as a list of our
current Consortium Members.

WWW: http://openinfosecfoundation.org
SVNWeb : Main Web Site : Distfiles Availability : PortsMon

NOTE: FreshPorts displays only information on required and default dependencies. Optional dependencies are not covered.

Required To Build:
  1. devel/gmake
  2. devel/pkgconf
  3. devel/automake
  4. devel/autoconf
Required Libraries:
  1. devel/pcre
  2. net/libnet
  3. textproc/libyaml
  4. devel/libhtp
  5. security/libprelude
There are no ports dependent upon this port

To install the port: cd /usr/ports/security/suricata/ && make install clean
To add the package: pkg install security/suricata


Configuration Options
===> The following configuration options are available for suricata-2.0.4:
     GEOIP=off: Enable GeoIP support for Suricata
     HTP_PORT=on: Use libhtp from ports instead of bundled
     IPFW=on: Enable IPFW and IP Divert support for inline IDP
     JSON=off: Enable Suricata JSON output
     PORTS_PCAP=off: Use libpcap from ports
     PRELUDE=on: Enable Prelude support for NIDS alerts
     TESTS=off: Enable unit tests in suricata binary
===> Use 'make config' to modify these settings

Master Sites:
  1. http://distcache.FreeBSD.org/ports-distfiles/
  2. http://mirrors.rit.edu/zi/
  3. http://www.openinfosecfoundation.org/download/

Number of commits found: 39

Commit History - (may be incomplete: see SVNWeb link above for full details)
DateByDescription
11 Nov 2014 15:57:53
Original commit files touched by this commit  2.0.4
Revision:372453
garga search for other commits by this committer
- Update suricata to 2.0.4 [1]
- Added JSON knob - this allows Suricata to be compiled with JSON output support
- Added GEOIP knob - this allows Suricata to support rules with geoip word
- Added HTP_PORT knob - this make the use of www/libhtp-suricata optional. E.g.
  user can choose between build-in and port version.
- Unbreak PLIST renaming sample files from -sample to .sample

PR:		193220 [1]
Submitted by:	cheffo [1]
Approved by:	maintainer timeout (> 2 months)
Security:	CVE-2014-6603
31 Oct 2014 15:40:38
Original commit files touched by this commit  2.0.3
Revision:371859
bapt search for other commits by this committer
Simplify plist by using @sample and @dir
23 Aug 2014 12:08:16
Original commit files touched by this commit  2.0.3
Revision:365723
koobs search for other commits by this committer
security/suricata: Update to 2.0.3, Modernize

Now that libprelude is safe from EXPIRE and has been staged [1], and
devel/libhtp
now *actually* links against libiconv even though autoconf detection was fine
[2] ... Have fun!

- Update to 2.0.3
- Switch libhtp to the upstream version port (devel/libhtp)
- Use USES=libtool
- Use OPTIONS helpers and other OPTIONS_* goodies
- Sort USE(S)* section
- Deprecate USE_AUTOTOOLS (USES instead)
- Deprecate AUTOMAKE_ARGS, ACLOCAL_ARGS (no longer necessary)
- Update COMMENT
- Add m4 macro for checking compiler flags and add relevent
  check to configure.ac. Our GCC doesn't like
  -Wno-error=unused-result and upstreams configure bits arent as
  portable as they could be.

[1] http://svnweb.freebsd.org/changeset/ports/365562
[2] http://svnweb.freebsd.org/changeset/ports/364955

Requested by:	many
21 Aug 2014 14:58:55
Original commit files touched by this commit  1.4.6_3
Revision:365562
koobs search for other commits by this committer
security/libprelude: Take MAINTAINER'ship, STAGE & Modernize

- Take Maintainership
- Enable STAGE support
- Tweak MASTER_SITES https -> http (portlint)
- Add LICENSE and LICENSE_FILE
- Deprecate USE_AUTOTOOLS for libtool (-> USES)
- Sort USES and OPTIONS
- Use OPTIONS helpers as much as possible for now [1]
- Add --enable-static to CONFIGURE_ARGS to retain the static lib
- Assign and Use ETCDIR rather than hardcoding
- Use the install-strip install target
- Update pkg-plist, use @sample and other goodies

While I'm here, bump dependent ports since our SHLIB major version has
changed

[1] https://reviews.freebsd.org/D665

Approved by: portmgr (implicit, bump unstaged port)
16 Jul 2014 08:44:05
Original commit files touched by this commit  1.4.6_2
Revision:362053
bapt search for other commits by this committer
Fix some non default LIB_DEPENDS

With hat:	portmgr
14 Jul 2014 15:38:39
Original commit files touched by this commit  1.4.6_2
Revision:361791  Sanity Test Failure
tijl search for other commits by this committer
- Convert net/libnet to USES=libtool and bump dependent ports
- Add INSTALL_TARGET=install-strip

Approved by:	portmgr (implicit, bump unstaged port)
05 Dec 2013 11:58:23
Original commit files touched by this commit  1.4.6_1
Revision:335661
koobs search for other commits by this committer
security/suricata: Remove unsupported DAG (Endace Capture) OPTION

This OPTION is non-functional as it requires hardware support and libdag from
Endace, which is not available in, nor recommended to be built via the ports
tree.

This OPTION also incorrectly added CONFIGURE_ARGS without adding any
LIB_DEPENDS, which broke configure: during build when the option was enabled.

Reported by:	mat (via pkg-fallout, via IRC)
17 Nov 2013 03:09:13
Original commit files touched by this commit  1.4.6
Revision:334051
koobs search for other commits by this committer
security/suricata: Update to 1.4.6, Switch to libhtp-suricata, Un-BROKEN Clang.

- Update to 1.4.6
- Switch to the correct library in www/libhtp-suricata
- Take maintainership
- Enable STAGE support
- Remove uneccessary patches
- Configure: Add libhtp include and library location
- Configure: Add /var to --localstatedir
- Configure: Disable Python support explicitly
- QA: Remove BROKEN with clang
- QA: Update to new LIB_DEPENDS format
- QA: Use ETCDIR instead of custom path for CONFIG_DIR and RULES_DIR
- QA: Replace hardcoded strings with ${PORTNAME}
- QA: Add documentation and %%DOCSDIR%% to pkg-plist
(Only the first 15 lines of the commit message are shown above View all of this commit message)
20 Sep 2013 22:55:26
Original commit files touched by this commit  1.3.4_3
Revision:327769
bapt search for other commits by this committer
Add NO_STAGE all over the place in preparation for the staging support (cat:
security)
30 Apr 2013 23:16:21
Original commit files touched by this commit  1.3.4_3
Revision:316970
wxs search for other commits by this committer
Take this port under my wing.
28 Apr 2013 14:05:44
Original commit files touched by this commit  1.3.4_3
Revision:316727
zi search for other commits by this committer
- Back to the pool
23 Apr 2013 14:20:28
Original commit files touched by this commit  1.3.4_3
Revision:316355
bapt search for other commits by this committer
Finish converting the whole ports tree to USES=pkgconfig
18 Feb 2013 21:13:02
Original commit files touched by this commit  1.3.4_3
Revision:312526
dinoex search for other commits by this committer
- update libnet to 1.1.6
- build shared lib
- fix dependend ports when libnet.so.8 was linked in
- fix dependend ports when includes where missing
15 Dec 2012 23:52:36
Original commit files touched by this commit  1.3.4_2
Revision:308972
pawel search for other commits by this committer
Bump ports affected by security/libprelude update
10 Dec 2012 19:11:12
Refresh Original commit files touched by this commit
Revision:308630  Sanity Test Failure
mm search for other commits by this committer
Update PCRE to 8.32
Introduces the UTF-32 library pcre32
Bump PORTREVISION in dependent ports
18 Nov 2012 05:52:08
Original commit files touched by this commit  1.3.4
Revision:307528
zi search for other commits by this committer
- Update to 1.3.4

Feature safe:	yes
02 Nov 2012 19:10:30
Original commit files touched by this commit  1.3.3
Revision:306882
zi search for other commits by this committer
- Update to 1.3.3

Feature safe:	yes
10 Oct 2012 11:42:05
Original commit files touched by this commit  1.3.2
Revision:305642
zi search for other commits by this committer
- Update to 1.3.2
06 Sep 2012 02:17:33
Original commit files touched by this commit  1.3.1
Revision:303732
zi search for other commits by this committer
- Update to 1.3.1
06 Sep 2012 02:07:35
Original commit files touched by this commit  1.3_1
Revision:303731
zi search for other commits by this committer
- Add in workaround for compatibility with libhtp >= 0.3
- Bump PORTREVISION
26 Jul 2012 05:40:24
Original commit files touched by this commit  1.3
bapt search for other commits by this committer
new devel/pkgconf added to replace devel/pkg-config. new version of pkg-config
are no more self hosting so we are stuck with 0.25 version while pkgconf provide
the same set of features as 0.27 and a compatible frontend. A symlink to
pkg-config has been added for convenience and compatibility

This also introduces a new macro to use pkgconf in your ports:
USE_PKGCONFIG

it can take the following arguments:
 - yes (meaning build only dep)
 - build (meaning build only dep)
 - run (meaning run only dep)
 - both (meaning run and build dep)

From now USE_GNOME= pkgconfig is deprecated in favour of USE_PKGCONFIG
The old gnome macro has been modified to use pkgconf but still the sameway: run
and build dep to avoid large breakage.

While here fix some ports relying on pkg-config but not specifying it, fix some
ports broken because testing wrong .pc files, and fix ports using pkg-config
--version to determine pkg-config version instead of
pkg-config --modversion pkg-config like recommanded by pkg-config

With Hat:	portmgr
Exp-runs by:	bapt (pointhat-west), beat (pointyhat)
16 Jul 2012 11:18:35
Original commit files touched by this commit  1.3
zi search for other commits by this committer
- Mark BROKEN when compiling with clang
11 Jul 2012 02:36:53
Original commit files touched by this commit  1.3
zi search for other commits by this committer
- Update to 1.3
- Convert to OptionsNG
11 May 2012 20:38:09
Original commit files touched by this commit  1.2.1_1
ade search for other commits by this committer
Update autoconf to 2.69 and automake to 1.12

PR:             166836
Tested by:      Multiple -exp runs (pav)
23 Mar 2012 14:27:51
Original commit files touched by this commit  1.2.1_1
zi search for other commits by this committer
- Update mirror URL on my ports

Feature safe:   yes
13 Mar 2012 12:04:26
Original commit files touched by this commit  1.2.1_1
zi search for other commits by this committer
- Do not overwrite files from devel/libhtp [1]
- Do not overwrite customized config files [1]
- Optionally depend on libpcap from ports (off by default) [1]
- Detect and use gcc hardening options by default
- Cleanup language/whitespace
- Bump PORTREVISION

PR:             ports/164237 [1]
Submitted by:   Geoffroy Desvernay <dgeo@centrale-marseille.fr> [1]
Feature safe:   yes
23 Feb 2012 14:05:49
Original commit files touched by this commit  1.2.1
zi search for other commits by this committer
- Update to 1.2.1 [1]
- Reset maintainership due to multiple maintainer timeouts
- Take maintainership

PR:             ports/164471 [1]
Submitted by:   Nikolay Denev <ndenev@gmail.com> [1]
14 Feb 2012 12:45:35
Original commit files touched by this commit  1.1.1_1
mm search for other commits by this committer
Bump pcre library dependency due to 8.30 update
14 Jan 2012 08:57:23
Original commit files touched by this commit  1.1.1
dougb search for other commits by this committer
In the rc.d scripts, change assignments to rcvar to use the
literal name_enable wherever possible, and ${name}_enable
when it's not, to prepare for the demise of set_rcvar().

In cases where I had to hand-edit unusual instances also
modify formatting slightly to be more uniform (and in
some cases, correct). This includes adding some $FreeBSD$
tags, and most importantly moving rcvar= to right after
name= so it's clear that one is derived from the other.
10 Jan 2012 19:34:02
Original commit files touched by this commit  1.1.1
wxs search for other commits by this committer
- Update to 1.1.1.
- Use libhtp from ports instead of the bundled one.
- Remove check for 6.x.

PR:             ports/163603
Submitted by:   wxs@
Approved by:    eksffa@freebsdbrasil.com.br (maintiner timeout)
08 Jan 2012 07:01:25
Original commit files touched by this commit  1.0.3
eadler search for other commits by this committer
Repeated words are are hard to to find sometimes.

Approved by:    portmgr (itetcu)
19 Jul 2011 21:14:31
Original commit files touched by this commit  1.0.3
zi search for other commits by this committer
Add DAG Support
Fix build when using custom LOCALBASE/PREFIX
Pacify portlint(1)

PR:             ports/158147
Submitted by:   rpsfa@rit.edu (me)
Approved by:    maintainer timeout, tabthorpe (mentor)
22 Jun 2011 00:29:16
Original commit files touched by this commit  1.0.3
wxs search for other commits by this committer
- Update to 1.0.3.
- Add LICENSE.

PR:             ports/157860
Submitted by:   Ryan Steinmetz <rpsfa@rit.edu>
Approved by:    Patrick Tracanelli <eksffa@freebsdbrasil.com.br> (maintainer)
04 Dec 2010 07:34:27
Original commit files touched by this commit  1.0.1_1
ade search for other commits by this committer
Sync to new bsd.autotools.mk
16 Oct 2010 11:52:47
Original commit files touched by this commit  1.0.1_1
ade search for other commits by this committer
Punt autoconf267->autoconf268
17 Sep 2010 09:31:03
Original commit files touched by this commit  1.0.1_1
linimon search for other commits by this committer
Mark as broken on sparc64 (and, by implication, the other tier-2 archs).

Hat:            portmgr
15 Sep 2010 18:35:24
Original commit files touched by this commit  1.0.1_1
ade search for other commits by this committer
Autotools update.   Read ports/UPDATING 20100915 for details.

Approved by:    portmgr (for Mk/bsd.port.mk part)
Tested by:      Multiple -exp runs
09 Sep 2010 11:41:48
Original commit files touched by this commit  1.0.1
pav search for other commits by this committer
- Mark BROKEN on 6.X: does not configure

PR:             ports/150393 (based on)
Submitted by:   Patrick Tracanelli <eksffa@freebsdbrasil.com.br> (maintainer)
01 Sep 2010 15:31:52
Original commit files touched by this commit  1.0.1
jmelo search for other commits by this committer
The Suricata Engine is an Open Source Next Generation Intrusion Detection and
Prevention Engine developed by the Open Information Security Foundation (OISF).

This engine is not intended to just replace or emulate the existing tools in
the industry, but will bring new ideas and technologies to the field.

OISF is part of and funded by the Department of Homeland Security's Directorate
for Science and Technology HOST program (Homeland Open Security Technology),
by the the Navy's Space and Naval Warfare Systems Command (SPAWAR), as well as
through the very generous support of the members of the OISF Consortium.

More information about the Consortium is available, as well as a list of our
current Consortium Members.

The Suricata Engine and the HTP Library are available to use under the GPLv2.

The HTP Library is an HTTP normalizer and parser written by Ivan Ristic of
Mod Security fame for the OISF. This integrates and provides very advanced
processing of HTTP streams for Suricata. The HTP library is required by the
engine but may also be used independently in a range of applications and tools.

WWW: http://openinfosecfoundation.org

PR:             ports/150191
Submitted by:   Patrick Tracanelli <eksffa@freebsdbrasil.com.br>

Number of commits found: 39

Login
User Login
Create account

Servers and bandwidth provided by
New York Internet, SuperNews, and RootBSD

This site
What is FreshPorts?
About the authors
FAQ
How big is it?
The latest upgrade!
Privacy
Forums
Blog
Contact

Search
Enter Keywords:
 
more...

Latest Vulnerabilities
flacNov 25
asterisk11Nov 21
asterisk11Nov 21
phpmyadminNov 21
kde4-runtimeNov 20
kwebkitpartNov 20
yiiNov 19
chromiumNov 18
kde4-workspaceNov 17
dbusNov 11
wgetNov 08
konversation-kde4Nov 05
jenkinsOct 31
jenkins-ltsOct 31
twikiOct 31

9 vulnerabilities affecting 11 ports have been reported in the past 14 days

* - modified, not new

All vulnerabilities


Ports
Home
Categories
Deleted ports
Sanity Test Failures
Newsfeeds


Statistics
Graphs
NEW Graphs (Javascript)
Traffic

Calculated hourly:
Port count 24392
Broken 162
Deprecated 79
Ignore 419
Forbidden 1
Restricted 206
No CDROM 93
Vulnerable 18
Expired 12
Set to expire 74
Interactive 0
new 24 hours 7
new 48 hours10
new 7 days52
new fortnight182
new month237

Servers and bandwidth provided by
New York Internet, SuperNews, and RootBSD
Valid HTML, CSS, and RSS.
Copyright © 2000-2014 Dan Langille. All rights reserved.