Suricata v7 add sys_nice cap

Is there a way to add sys_nice cap in order to run Suricata v7 via Vyos config?

Running latest Vyos 1.5 rolling.


If you don’t mind building the VyOS package yourself, you just need to add them as config options to the /interface-definitions/ in the vyos/vyos-1x repository.

I built it as a quick test and it works fine:

vyos@vyos# show container name zt1 cap-add | commands
set cap-add 'net-admin'
set cap-add 'sys-admin'
set cap-add 'sys-nice'

vyos@vyos# sudo podman container inspect zt1 | jq '.[0].HostConfig.CapAdd'

If you don’t want to mess with that, you can edit this file locally on your installed VyOS to expose the configuration item:


Created a pull request to have this included in rolling at some point. Thanks for the help!


No problem! I added a comment to your PR asking if you can update the completionHelp list and add a valueHelp element.

1 Like

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.