i was checking our IPFire system today and one point was the IDS rules page.
I see that the system is running with an old set of rules (9th of april) so my first thinking was that i forgot to enable the automatic update.
The IDS page shows me that automatic updates are enabled.
The next look was into the cron log and here my question came up.
I can see nothing in the cron log. On no day since i reinstalled the system i have a entry in this log.
The cron service (fcron) is running, I checked it from the GUI and also from the console and I have a cronfile for the root user with some ipfire related entries.
Normaly i would expect that the cron log shows me something like cron xxx running at and some infos about the job (normal cron infos) but the not running updates in combination with no entries in the log makes me a little bit nervous.
How can I check if fcron is running correct and where are the update rules for the IDS if not in the fcron file?
The updater line is not directly in the fcrontab. Depending on whether you have selected daily or weekly then a symlink is made in the /etc/fcron,daily or /etc/fcron.weekly folder
I have mine set to daily and my fcron.daily folder is as follows
-rw-r–r-- 1 root root 33 Feb 22 2021 info.txt
-rwxr-x— 1 root root 4.1K Dec 19 12:57 openvpn-crl-updater
lrwxrwxrwx 1 root root 33 Mar 29 15:12 suricata → /usr/local/bin/update-ids-ruleset
-rwxr-xr-x 1 root root 126 Mar 26 2021 trim
If there is no symlink in either the daily or weekly then if you change the setting from daily, if that is what it is set to currently, to weekly and press the save button and then change back to daily and press the save button then you should find the symlink present again in the daily folder.
If daily is selected and no symlink is present then just pressing save is not enough. You need to change the setting to another one, save and then go back to the setting you want and save.
Thanks for the Info this helps a lot.
I can not find any surricata entries in /var/log/messages over the last week except the ones from this morning where I was working on the system.
I now disabled/enabled all update rules and will see what happens tomorrow (I have daily updates enabled):
But thanks again for the infos so I’m a little bit calmed down that the normal cron stuff is running.