stamparm/maltrail

[Questions] How to enable only selected trails?

Closed this issue · 5 comments

Question
Any option for enable only selected trails?

For example, disable all trails and add to whitelist some trails for detection.

Hello!

Take a look on DISABLED_FEEDS (https://github.com/stamparm/maltrail/blob/master/maltrail.conf#L61-L62) and #DISABLED_TRAILS_INFO_REGEX (https://github.com/stamparm/maltrail/blob/master/maltrail.conf#L67-L68) parameters of /maltrail.conf file.

Hope, this is OK for you.

Thanks, I have read the existing functionality - it works like a blacklist. (All enabled - some disabled)
I am looking for an opportunity to apply - whitelist. (All disabled - some enabled).

Is it possible?

First variant only: All enabled - some disabled.

Dirty workaround for your case I suppose -- move (via F6) all uneeded trails/feeds files (I mean, .py for feeds and .txt for static trails) to some spare folder out of MT's working catalog, leave needed trails only and restart the /sensor.py.

Hello! Closing the ticket?

Considering as resolved